An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control and gain complete access to the application via modifying a HTTP header.
References
| Link | Resource |
|---|---|
| https://seclists.org/fulldisclosure/2024/Mar/0 | Exploit Third Party Advisory |
| http://seclists.org/fulldisclosure/2024/Mar/0 | |
| https://seclists.org/fulldisclosure/2024/Mar/0 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-03-06 00:15
Updated : 2025-11-04 19:15
NVD link : CVE-2023-38944
Mitre link : CVE-2023-38944
CVE.ORG link : CVE-2023-38944
JSON object : View
Products Affected
multilaser
- re160v_firmware
- re163v_firmware
- re163v
- re160v
CWE
CWE-269
Improper Privilege Management
