CVE-2022-45724: Medium severity Comfast Cf-wr610n Firmware vulnerability
Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSIONID, and using this SESSIONID an attacker can then perform authenticated requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45724?
CVE-2022-45724 is classified as a medium severity vulnerability due to the potential for remote unauthorized access.
How do I fix CVE-2022-45724?
To fix CVE-2022-45724, update the Comfast router CF-WR6110N to the latest firmware version available.
What does CVE-2022-45724 allow an attacker to do?
CVE-2022-45724 allows an attacker on the same network to exploit incorrect access control and perform authenticated requests.
Who is affected by CVE-2022-45724?
Users of the Comfast CF-WR6110N router running firmware version 2.3.1 are affected by CVE-2022-45724.
Is CVE-2022-45724 a local or remote attack?
CVE-2022-45724 is a remote attack that requires an attacker to be on the same network as the affected device.