Incorrect Access Control in Comfast router CF-WR6110N V2...
Moderate severity
Unreviewed
Published
Feb 13, 2023
to the GitHub Advisory Database
•
Updated Mar 24, 2025
Description
Published by the National Vulnerability Database
Feb 13, 2023
Published to the GitHub Advisory Database
Feb 13, 2023
Last updated
Mar 24, 2025
Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated requests.
References