Description
An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior enables an unauthenticated remote attacker to bypass authentication via a specially crafted direct request when another user has an active session.
Scores
CVSS v3
8.6
EPSS
0.0017
EPSS Percentile
37.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-425
Status
published
Products (14)
vonets/vap11ac_firmware
< 3.3.23.6.9
vonets/vap11g-300_firmware
< 3.3.23.6.9
vonets/vap11g-500_firmware
< 3.3.23.6.9
vonets/vap11g-500s_firmware
< 3.3.23.6.9
vonets/vap11g_firmware
< 3.3.23.6.9
vonets/vap11n-300_firmware
< 3.3.23.6.9
vonets/vap11s-5g_firmware
< 3.3.23.6.9
vonets/vap11s_firmware
< 3.3.23.6.9
vonets/var11n-300_firmware
< 3.3.23.6.9
vonets/var1200-h_firmware
< 3.3.23.6.9
... and 4 more
Published
Aug 12, 2024
Tracked Since
Feb 18, 2026