Description
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the return-url parameter to /goform/formLogout.
References (1)
Core 1
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://www.riskbasedsecurity.com/research/RBS-2016-004.pdf
Scores
CVSS v3
6.1
EPSS
0.0077
EPSS Percentile
50.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (3)
jensenofscandinavia/al3g_firmware
2.23m
jensenofscandinavia/al5000ac_firmware
1.13
jensenofscandinavia/al59300_firmware
1.04
Published
Apr 03, 2017
Tracked Since
Feb 18, 2026