CVE Tools

Семечко от Mango. Разбираем и воспроизводим уязвимость в роутере по описанию с NVD

Хакер (xakep.ru)By cu63

PoC publicGL-MT300N-V2 Mango

Our summary

Security researchers have successfully replicated the logic flaw described in CVE-2023-50920, demonstrating how predictable session handling compromises user identity on specific hardware. The investigation focused on the GL.iNet GL-MT300N-V2 "Mango" running firmware version 4.3.7, which fails to rotate session identifiers after a reboot. This behavior allows attackers to reuse captured session tokens to bypass authentication controls and impersonate legitimate users.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store