Improper access control in InRouter 615 and InRouter302 - CVE-2023-22600

 

Improper access control in InRouter 615 and InRouter302 - CVE-2023-22600

Published: January 13, 2023 / Updated: January 16, 2023


Vulnerability identifier: #VU71153
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22600
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the affected products allow unauthenticated devices to subscribe to MQTT topics on the same network as the device manager. A remote attacker can send GET/SET configuration commands, reboot commands, and push firmware updates.


Affected software

InRouter 615
InRouter302

How to mitigate CVE-2023-22600

Install updates from vendor's website.

InRouter 615 - update to 2.3.0.r5542
InRouter302 - update to 3.5.56

External References

Related Security Bulletins