Impact
CentreStack versions before 17.4 allow an attacker to inject arbitrary session variables by embedding newline and tab characters into the AccountName parameter sent to the SelectProvider.aspx endpoint. The custom session serialization format does not sanitize these control characters, enabling the injection of a resellerid session variable. This bypasses the IsValidRSession authentication check, allowing attackers to gain unauthorized access to the system’s management pages and potentially compromise other administrative functions.
Affected Systems
The vulnerability affects all instances of Gladinet CentreStack deployed with a version number less than 17.4. No specific sub‑version details are provided, so any build prior to the 17.4 release is considered at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation under current conditions. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires unauthenticated access to the web application and a crafted HTTP POST request to the SelectProvider.aspx endpoint. Attackers do not need privileged system access beyond the ability to send requests to the target server.
OpenCVE Enrichment