logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-33621

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-33621

Description:
GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.
Last updated date:
06/23/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/23/2023
Reference url to background

https://justinapplegate.me/2023/glinet-CVE-2023-33621/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy