Information disclosure - CVE-2016-4968
Published: September 8, 2016 / Updated: September 8, 2016
Detailed vulnerability description
The vulnerability allows an authenticated low privileged user to get access to administrator’s cookies.
The vulnerability exists due to an error when handling GET requests of the /linkreport/tmp/admin_global page. A remote authenticated attacker can send a specially crafted HTTP GEt request and obtain administrator’s cookies.
Successful exploitation of this vulnerability may allow attackers to gain full access to vulnerable device.