CVE-2017-20223
CRITICALTelesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference
Title source: cnaDescription
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive information and access functionalities without proper access controls.
Exploits (1)
References (6)
Scores
CVSS v3
9.8
EPSS
0.0002
EPSS Percentile
6.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-639
Status
published
Products (2)
Telesquare/SDT-CS3B1
1.2.0
telesquare/sdt-cs3b1_firmware
1.2.0
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026