Back

CRITICAL

Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts

Published Nov 3, 2023

Description

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.

Affected products

Remediation

Vendor solution

Update version to G040WQR231013.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Nov 3, 2023
Updated Sep 6, 2024
Reserved Aug 29, 2023
CISA Vulnrichment
Updated Sep 5, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a