CVE-2023-41353

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-7503-a27ed-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nokia:g-040w-q_firmware:g040wqr201207:*:*:*:*:*:*:*
cpe:2.3:h:nokia:g-040w-q:-:*:*:*:*:*:*:*

History

13 Nov 2023, 19:31

Type Values Removed Values Added
CWE CWE-521
References (MISC) https://www.twcert.org.tw/tw/cp-132-7503-a27ed-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-7503-a27ed-1.html - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Nokia
Nokia g-040w-q
Nokia g-040w-q Firmware
CPE cpe:2.3:h:nokia:g-040w-q:-:*:*:*:*:*:*:*
cpe:2.3:o:nokia:g-040w-q_firmware:g040wqr201207:*:*:*:*:*:*:*

03 Nov 2023, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-03 06:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-41353

Mitre link : CVE-2023-41353

CVE.ORG link : CVE-2023-41353


JSON object : View

Products Affected

nokia

  • g-040w-q_firmware
  • g-040w-q
CWE
CWE-521

Weak Password Requirements