Impact
A flaw in the realIP function of MegaEase EaseProbe’s middleware allows an attacker to manipulate the X-Forwarded-For, X-Real-IP and True-Client-IP headers. By forging these headers, the middleware can be tricked into treating traffic as originating from an authorized IP address, thereby bypassing its intended IP‑based access controls and potentially gaining unauthorized access to protected resources.
Affected Systems
All installations of MegaEase EaseProbe up to version 2.3.0 are affected. The vulnerability resides in the web/server.go component of the middleware.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. An attacker can initiate the exploit remotely by sending a crafted HTTP request that includes forged X-Forwarded-For, X-Real-IP or True-Client-IP headers, thereby bypassing authorization checks that occur before the application processes the request. The exploit has been published, raising the risk of in‑the‑wild attacks.
OpenCVE Enrichment