GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Jan 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-03T02:24:34.729Z
Reserved: 2023-05-22T00:00:00
Link: CVE-2023-33621

Updated: 2024-08-02T15:47:06.473Z

Status : Modified
Published: 2023-06-13T16:15:13.027
Modified: 2024-11-21T08:05:46.173
Link: CVE-2023-33621

No data.