CVE-2023-49262: Hongdian h8951-4g-Esp Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.

Affected products

  • Hongdian h8951-4g-Esp Firmware: before 2310271149 (fixed in 2310271149)

Published 2024-01-12. Last modified 2026-06-17.