An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files.
2023-04-15T00:15:07.527
2025-02-10T16:15:34.290
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | commscope | dg3450_firmware | ar01.02.056.18_041520_711.ncs.10 | Yes |
Hardware | commscope | dg3450 | - | No |