CRITICAL🇵🇱 Wersja polska

CVE-2023-41351

CVSS 9.8v3.1pub. 2023-11-03upd. 2024-11-21

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Nokia G 040w Q

    HW
    Nokia
    all versions
  • Nokia G 040w Q Firmware

    OS
    Nokia
    g040wqr201207
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-41355CRITICAL9.8PL ✓same product

Nokia G-040W-Q: brak walidacji komunikatów ICMP redirect w firewall

CVE-2023-41350HIGH7.5same product

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authen...

CVE-2023-41352HIGH7.2same product

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacke...

CVE-2023-41353HIGH8.8same product

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regu...

CVE-2023-41354MEDIUM4.0same product

Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauth...