CVE-2023-38945

EUVD-2023-42705
Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_pt allows attackers to bypass the access control and gain complete access to the application via supplying a crafted URL.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
Affected Products (NVD)
VendorProductVersion
multilaserre160_firmware
5.07.51_pt_mtl01:_pt_mtl01
multilaserre160_firmware
5.07.52_pt_mtl01:_pt_mtl01
multilaserre160v_firmware
12.03.01.08_pt:_pt
multilaserre160v_firmware
12.03.01.09_pt:_pt
multilaserre163v_firmware
12.03.01.08_pt:_pt
𝑥
= Vulnerable software versions