This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and password from the web interface (Login Page) of the vulnerable targeted system.
References
| Link | Resource |
|---|---|
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0013 | Third Party Advisory |
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0013 | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
21 Nov 2024, 08:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0013 - Third Party Advisory |
20 Jan 2024, 02:47
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-01-17 08:15
Updated : 2024-11-21 08:38
NVD link : CVE-2023-51740
Mitre link : CVE-2023-51740
CVE.ORG link : CVE-2023-51740
JSON object : View
Products Affected
skyworthdigital
- cm5100_firmware
- cm5100
CWE
CWE-319
Cleartext Transmission of Sensitive Information
