CVE-2023-49255
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-49255 is a vulnerability affecting routers where the console is accessible without authentication through the "data" field. Although modifying the configuration requires being logged in, session states are shared. If another user is currently logged in, an anonymous user can execute commands in the context of the authenticated user. This poses a significant risk, especially if the logged-in user holds administrative privileges. Unauthorized users can exploit this vulnerability to create new admin accounts with chosen passwords using the webadmin service configuration commands.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.