Improper access control in InRouter 615 and InRouter302 - CVE-2023-22600
Published: January 13, 2023 / Updated: January 16, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected products allow unauthenticated devices to subscribe to MQTT topics on the same network as the device manager. A remote attacker can send GET/SET configuration commands, reboot commands, and push firmware updates.
Affected software
InRouter302
How to mitigate CVE-2023-22600
InRouter302 - update to 3.5.56