CVE-2017-20223

CRITICAL

Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference

Title source: cna

Description

Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive information and access functionalities without proper access controls.

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/43402

Scores

CVSS v3 9.8
EPSS 0.0002
EPSS Percentile 6.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-639
Status published
Products (2)
Telesquare/SDT-CS3B1 1.2.0
telesquare/sdt-cs3b1_firmware 1.2.0
Published Mar 16, 2026
Tracked Since Mar 16, 2026