go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts

TVN ID TVN-202311006
CVE ID CVE-2023-41350
CVSS 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products Chunghwa Telecom NOKIA G-040W-Q: G040WQR201207
Description Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.
Solution Update version to 3.0.0.4.386_51948.
Credit Ta-Lun Yen(TXOne Networks)
Public Date 2023-11-03
Top