First published: Fri Nov 03 2023(Updated: )
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia G-040w-q Firmware | =g040wqr201207 | |
NOKIA G-040W-Q |
Update version to G040WQR231013.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-41350.
The title of this vulnerability is 'Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts'.
The severity level of CVE-2023-41350 is critical with a severity value of 9.8.
This vulnerability affects Chunghwa Telecom NOKIA G-040W-Q by allowing an unauthenticated remote attacker to execute a crafted Javascript to expose captcha on the page, making it easier for bots to bypass the captcha check.
There is no information available about a fix for CVE-2023-41350 at the moment.