CVE-2024-8888
CRITICALCircutor Q-smt Firmware - Insufficient Session Expiration
Title source: ruleDescription
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods such as network captures, locally stored web information, etc.
Scores
CVSS v3
10.0
EPSS
0.0027
EPSS Percentile
50.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-613
Status
published
Products (1)
circutor/q-smt_firmware
1.0.4
Published
Sep 18, 2024
Tracked Since
Feb 18, 2026