CVE-2023-49261
12.01.2024, 15:15
The "tokenKey" value used in user authorization is visible in the HTML source of the login page.Enginsight
Vendor | Product | Version |
---|---|---|
hongdian | h8951-4g-esp_firmware | 𝑥 < 2310271149 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-201 - Insertion of Sensitive Information Into Sent DataThe code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.