We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-41351

Chunghwa Telecom NOKIA G-040W-Q - Broken Access Control



Assignertwcert
Reserved2023-08-29
Published2023-11-03
Updated2024-09-04

Description

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.



CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-288 Authentication Bypass Using an Alternate Path or Channel

Product status

Default status
0x40028d6b10

G040WQR201207
affected

References

https://www.twcert.org.tw/tw/cp-132-7501-6155a-1.html

cve.org CVE-2023-41351

nvd.nist.gov CVE-2023-41351

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-41351
Subscribe to our newsletter to learn more about our work.