CVE-2024-1623

HIGH

Sagemcom F@ST 3686 Firmware < 3.709.2 - Insufficient Session Expiration in Login/Logout Handler

Title source: llm
STIX 2.1

Description

Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without requiring login credentials. This vulnerability is possible because the 'Login.asp and logout.asp' files do not handle session details correctly.

Scores

CVSS v3 7.7
EPSS 0.0018
EPSS Percentile 7.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-613
Status published
Products (1)
sagemcom/f\@st_3686_firmware < 3.709.2
Published Mar 14, 2024
Tracked Since Feb 18, 2026