Insufficient Session Expiration vulnerability on CIRCUTOR Q-SMT
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 0.4%
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
nono source reports it
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods such as network captures, locally stored web information, etc.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
CIRCUTOR · CIRCUTOR Q-SMT