Skr11lex / CVE-2023-33477

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2023-33477

Harmonic NSG 9000-6G modulator has an unauthorized download vulnerability in the config.exp configuration file

Due to the lack of access permission verification for the "cgi.bin/config.exp" file in this model modulator, any user may request to download a configuration file while remotely connected. The configuration file contains a large number of sensitive interfaces and the request method is written in the file, allowing attackers to further test the device

About