NA

CVE-2023-38945

Published: 06/03/2024 Updated: 06/03/2024

Vulnerability Summary

Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_pt allows malicious users to bypass the access control and gain complete access to the application via supplying a crafted URL.

Exploits

Multilaser RE160V web management interface versions 12030108_pt and 12030109_pt along with RE160 versions 50751_pt_MTL01 and 50752_pt_MTL01 suffer from an access control bypass vulnerability through URL manipulation ...
Multilaser RE160 versions 50751_pt_MTL01 and 50752_pt_MTL01 suffer from an access control bypass vulnerability through cookie manipulation ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Multilaser Router - Access Control Bypass through Cookie Manipulation - CVE-2023-38946 <!--X-Subject-Header-End--> <!- ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Multilaser Router - Access Control Bypass through URL Manipulation - CVE-2023-38945 <!--X-Subject-Header-End--> <!--X- ...