#VU63973 Direct Request ('Forced Browsing') in Carrier products - CVE-2022-31485
Published: June 3, 2022
LNL-X2210
LNL-X2220
LNL-X3300
LNL-X4420
LNL-4420
S2-LP-1501
S2-LP-4502
S2-LP-2500
S2-LP-1502
Carrier
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files. A remote attacker can send a specially crafted packet to update the “notes” section on the home page of the web interface.