Improper Authorization in NBG7510 - CVE-2022-38546

 

Improper Authorization in NBG7510 - CVE-2022-38546

Published: December 21, 2022


Vulnerability identifier: #VU70458
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38546
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to a DNS misconfiguration. A remote non-authenticated attacker can perform DNS-related attacks, such as DNS tunneling or DNS amplification attacks, by using the open DNS resolver when the device is switched to the AP mode.

Affected software

NBG7510

How to mitigate CVE-2022-38546

Install updates from vendor's website.

NBG7510 - update to 1.00(ABZY.3)C0

External References

Related Security Bulletins