CVE-2021-38474

CVE-2021-38474

InHand Networks IR615 Router’s Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-force password attack with no time limitation and without harming the normal operation of the user. This could allow an attacker to gain valid credentials for the product interface.

Source: CVE-2021-38474

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다