CVE-2022-40494

NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ehang-io:nps:*:*:*:*:*:*:*:*

History

17 Apr 2025, 14:55

Type Values Removed Values Added
CPE cpe:2.3:a:nps_project:nps:*:*:*:*:*:*:*:* cpe:2.3:a:ehang-io:nps:*:*:*:*:*:*:*:*
First Time Ehang-io
Ehang-io nps

Information

Published : 2022-10-06 22:15

Updated : 2025-04-17 14:55


NVD link : CVE-2022-40494

Mitre link : CVE-2022-40494

CVE.ORG link : CVE-2022-40494


JSON object : View

Products Affected

ehang-io

  • nps
CWE
CWE-287

Improper Authentication