vendor:
Telesquare SKT LTE Router SDT-CS3B1
by:
Gjoko 'LiquidWorm' Krstic
5.5
CVSS
MEDIUM
Insecure Direct Object Reference
639
CWE
Product Name: Telesquare SKT LTE Router SDT-CS3B1
Affected Version From: FwVer: SDT-CS3B1, sw version 1.2.0
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: telesquare:sdt-cs3b1
Platforms Tested: Linux
2017
Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference Info Leak
This vulnerability allows attackers to bypass authorization and access resources and functionalities in the system by providing direct access to objects based on user-supplied input.
Mitigation:
Implement proper authorization checks and access controls to prevent unauthorized access to resources.