Impact
Missing authentication in a critical function of TR7 Cyber Defense Inc.'s WAF‑ASP creates a vulnerability that allows unauthenticated users to invoke privileged operations or view sensitive configuration data. This flaw is classified as CWE‑306, an improper login or authentication control, and is inferred from the description that authentication checks are absent. The lack of authentication checks suggests that any system using the exposed interface can be compromised if accessed by an attacker.
Affected Systems
TR7 Cyber Defense Inc.’s WAF‑ASP versions from 1.0.324.900 up through 1.4.0.116 are affected. Any appliance running one of these releases is vulnerable and requires an update to a fixed version.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity while the EPSS score below 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is reaching the WAF‑ASP management interface over the network, either internal or remote, which is inferred from the description that unauthenticated access is possible. Once network reachability is achieved, the attacker can trigger the unauthenticated endpoint, gaining unauthorized execution of privileged functions and potential access to protected resources. The exploitation path is straightforward in the presence of network reachability due to the absence of proper authentication control.
OpenCVE Enrichment