MEDIUM · 5.9

CVE-2023-33621

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or acce...

Vulnerability Description

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Gl-InetGl-Ar750S Firmware3.215
Gl-InetGl-Ar750S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-33621?

CVE-2023-33621 is a vulnerability with a CVSS score of 5.9 (MEDIUM). GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or acce...

How severe is CVE-2023-33621?

CVE-2023-33621 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-33621?

Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-Ar750S Firmware, Gl-Inet Gl-Ar750S.