9.8

CVE-2022-40055

An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GxgroupGpon Ont Titanium 2122a Firmware Versiont2122-v1.26exl
   GxgroupGpon Ont Titanium 2122a Versionc40-210
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.487
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

https://blog.alphathreat.in/index.php?post/2022/10/01/Achieving-CVE-2022-40055
Third Party Advisory