CVE-2020-26732

HIGH

SKYWORTH GN542VF - Info Disclosure

Title source: llm
STIX 2.1

Description

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

Exploits (1)

nomisec WRITEUP 1 stars
by swzhouu · poc
https://github.com/swzhouu/CVE-2020-26732

Scores

CVSS v3 7.5
EPSS 0.0021
EPSS Percentile 43.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-311
Status published
Products (1)
skyworth/gn542vf_boa_firmware 0.94.13
Published Jan 14, 2021
Tracked Since Feb 18, 2026