An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days