Aller au contenu

Fiche vulnérabilité

CVE-2023-41351 : faille critique nokia g-040w-q firmware (CVSS 9.8)

Description

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
3 nov. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • nokia g-040w-q firmware

Références

Rechercher une autre vulnérabilité dans la base CVE