The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials.
References
Link | Resource |
---|---|
https://github.com/Alkatraz97/CVEs/blob/main/CVE-2023-33754.md | Exploit Third Party Advisory |
https://github.com/Alkatraz97/CVEs/blob/main/CVE-2023-33754.md | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-06-01 20:15
Updated : 2025-01-09 17:15
NVD link : CVE-2023-33754
Mitre link : CVE-2023-33754
CVE.ORG link : CVE-2023-33754
JSON object : View
Products Affected
inpiazza
- cloud_wifi
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts