HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://uk.humaxdigital.com/network/hga12r-02/ | product vendor advisory |
https://medium.com/%40rsantos_14778/hijacked-session-cve-2020-9370-255bbd02975a |