The web management server for Red-M 1050 (Bluetooth Access Point) does not use session-based credentials to authenticate users, which allows attackers to connect to the server from the same IP address as a user who has already established a session.
Link | Tags |
---|---|
http://www.atstake.com/research/advisories/2002/a060502-1.txt | exploit patch vendor advisory |
http://www.securityfocus.com/bid/4940 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9265 | vdb entry |