Session Replay Vulnerability in GL.iNET GL-AR750S-Ext Firmware
CVE-2023-33621

5.9MEDIUM

Key Information:

Vendor

Gl-inet

Vendor
CVE Published:
13 June 2023

What is CVE-2023-33621?

The GL.iNET GL-AR750S-Ext firmware v3.215 is susceptible to a security issue where the admin authentication token is inadvertently included in a GET request during the download of the OpenVPN Server configuration file. This exposed token can be stored in browser history or access logs, which could allow unauthorized parties to perform session replay attacks, effectively bypassing normal authentication mechanisms and compromising the device's security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.