Семечко от Mango. Разбираем и воспроизводим уязвимость в роутере по описанию с NVD
PoC publicGL-MT300N-V2 MangoOur summary
Security researchers have successfully replicated the logic flaw described in CVE-2023-50920, demonstrating how predictable session handling compromises user identity on specific hardware. The investigation focused on the GL.iNet GL-MT300N-V2 "Mango" running firmware version 4.3.7, which fails to rotate session identifiers after a reboot. This behavior allows attackers to reuse captured session tokens to bypass authentication controls and impersonate legitimate users.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.