CVE-2022-33106

CRITICAL

WiJungle U250 Firmware - Unauthenticated Brute Force via Excessive Authentication Attempts

Title source: llm
STIX 2.1

Description

WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.

References (2)

Core 2
Core References

Scores

CVSS v3 9.8
EPSS 0.0083
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-307
Status published
Products (1)
wijungle/u250_firmware
Published Oct 12, 2022
Tracked Since Feb 18, 2026