An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
2021-12-29T13:15:07.803
2024-11-21T06:11:43.080
Modified
CVSSv3.1: 7.4 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | zyxel | nbg6604_firmware | < 1.00\(abir.9\)c0 | Yes |
| Hardware | zyxel | nbg6604 | - | No |