Improper Authorization in NBG7510 - CVE-2022-38546
Published: December 21, 2022
Vulnerability identifier: #VU70458
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38546
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to a DNS misconfiguration. A remote non-authenticated attacker can perform DNS-related attacks, such as DNS tunneling or DNS amplification attacks, by using the open DNS resolver when the device is switched to the AP mode.Affected software
NBG7510
How to mitigate CVE-2022-38546
Install updates from vendor's website.
NBG7510 - update to 1.00(ABZY.3)C0