Aller au contenu

Fiche vulnérabilité

CVE-2023-41350 : faille critique nokia g-040w-q firmware (CVSS 9.8)

Description

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
3 nov. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • nokia g-040w-q firmware

Références

Rechercher une autre vulnérabilité dans la base CVE