#VU63967 Direct Request ('Forced Browsing') in Carrier products - CVE-2022-31480
Published: June 3, 2022
LNL-X2210
LNL-X2220
LNL-X3300
LNL-X4420
LNL-4420
S2-LP-1501
S2-LP-4502
S2-LP-2500
S2-LP-1502
Carrier
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the affected application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files. A remote attacker can upload arbitrary firmware files to the target device and cause a denial of service condition on the system.