CVE-2023-41351: Chunghwa Telecom NOKIA G-040W-Q - Broken Access Control
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41351?
CVE-2023-41351 is a vulnerability of authentication bypass in Chunghwa Telecom NOKIA G-040W-Q.
How severe is CVE-2023-41351?
CVE-2023-41351 has a severity rating of 9.8, which is considered critical.
How does CVE-2023-41351 impact Chunghwa Telecom NOKIA G-040W-Q?
CVE-2023-41351 allows unauthenticated remote attackers to bypass the authentication mechanism and log in to the device using an alternative URL.
How can an attacker exploit CVE-2023-41351?
An unauthenticated remote attacker can exploit CVE-2023-41351 by bypassing the authentication mechanism and logging in as any existing user.
Is there a fix for CVE-2023-41351?
At the moment, there is no known fix for CVE-2023-41351. It is recommended to apply security patches or updates when they become available.