CVE-2017-20223
CVE-2017-20223
9.3
CriticalPublished:
Last updated:
Source:disclosure@vulncheck.com
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive information and access functionalities without proper access controls.
References
disclosure@vulncheck.com
https://cxsecurity.com/issue/WLB-2017120297disclosure@vulncheck.com
https://exchange.xforce.ibmcloud.com/vulnerabilities/136993disclosure@vulncheck.com
https://packetstormsecurity.com/files/145551disclosure@vulncheck.com
https://www.exploit-db.com/exploits/43402/disclosure@vulncheck.com
https://www.vulncheck.com/advisories/telesquare-skt-lte-router-sdt-cs3b1-insecure-direct-object-referencedisclosure@vulncheck.com
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5445.php