mod advisory
This commit is contained in:
parent
af492efdf8
commit
0db12a3c5e
@ -5,6 +5,7 @@ GLiNet: Router Authentication Bypass
|
|||||||
========================================================================
|
========================================================================
|
||||||
Contents
|
Contents
|
||||||
========================================================================
|
========================================================================
|
||||||
|
|
||||||
1. Overview
|
1. Overview
|
||||||
2. Detailed Description
|
2. Detailed Description
|
||||||
3. Exploit
|
3. Exploit
|
||||||
@ -13,6 +14,7 @@ Contents
|
|||||||
========================================================================
|
========================================================================
|
||||||
1. Overview
|
1. Overview
|
||||||
========================================================================
|
========================================================================
|
||||||
|
|
||||||
CVE-2023-46453 is a remote authentication bypass vulnerability in the web
|
CVE-2023-46453 is a remote authentication bypass vulnerability in the web
|
||||||
interface of GLiNet routers running firmware versions 4.x and up. The
|
interface of GLiNet routers running firmware versions 4.x and up. The
|
||||||
vulnerability allows an attacker to bypass authentication and gain access
|
vulnerability allows an attacker to bypass authentication and gain access
|
||||||
@ -21,6 +23,7 @@ to the router's web interface.
|
|||||||
========================================================================
|
========================================================================
|
||||||
2. Detailed Description
|
2. Detailed Description
|
||||||
========================================================================
|
========================================================================
|
||||||
|
|
||||||
The vulnerability is caused by a lack of proper authentication checks in
|
The vulnerability is caused by a lack of proper authentication checks in
|
||||||
/usr/sbin/gl-ngx-session file. The file is responsible for authenticating
|
/usr/sbin/gl-ngx-session file. The file is responsible for authenticating
|
||||||
users to the web interface. The authentication is in different stages.
|
users to the web interface. The authentication is in different stages.
|
||||||
|
Loading…
Reference in New Issue
Block a user