An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control and gain complete access to the application via modifying a HTTP header.
References
Link | Resource |
---|---|
https://seclists.org/fulldisclosure/2024/Mar/0 | Exploit Third Party Advisory |
https://seclists.org/fulldisclosure/2024/Mar/0 | Exploit Third Party Advisory |
Configurations
History
03 Jan 2025, 20:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://seclists.org/fulldisclosure/2024/Mar/0 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:h:multilaser:re160v:-:*:*:*:*:*:*:* cpe:2.3:h:multilaser:re163v:-:*:*:*:*:*:*:* cpe:2.3:o:multilaser:re163v_firmware:12.03.01.10_pt:*:*:*:*:*:*:* cpe:2.3:o:multilaser:re160v_firmware:12.03.01.09_pt:*:*:*:*:*:*:* |
|
First Time |
Multilaser re163v Firmware
Multilaser re163v Multilaser re160v Multilaser Multilaser re160v Firmware |
21 Nov 2024, 08:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://seclists.org/fulldisclosure/2024/Mar/0 - |
19 Aug 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-269 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
06 Mar 2024, 15:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
06 Mar 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-06 00:15
Updated : 2025-01-03 20:12
NVD link : CVE-2023-38944
Mitre link : CVE-2023-38944
CVE.ORG link : CVE-2023-38944
JSON object : View
Products Affected
multilaser
- re163v
- re163v_firmware
- re160v
- re160v_firmware
CWE
CWE-269
Improper Privilege Management