CVE-2023-41350: Nokia G-040w-Q Firmware

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.

Affected products

  • Nokia G-040w-Q Firmware: version g040wqr201207 only

Published 2023-11-03. Last modified 2026-06-17.