Session Replay Vulnerability in GL.iNET GL-AR750S-Ext Firmware
CVE-2023-33621
5.9MEDIUM
What is CVE-2023-33621?
The GL.iNET GL-AR750S-Ext firmware v3.215 is susceptible to a security issue where the admin authentication token is inadvertently included in a GET request during the download of the OpenVPN Server configuration file. This exposed token can be stored in browser history or access logs, which could allow unauthorized parties to perform session replay attacks, effectively bypassing normal authentication mechanisms and compromising the device's security.
