CVE-2015-6023 describes an access restriction bypass vulnerability in the ping.cgi component of NetCommWireless HSPA 3G10WVE wireless routers running firmware prior to 3G10WVE-L101-S306ETS-C01_R05. This flaw allows unauthenticated remote attackers to bypass intended security controls through a direct request. With a CVSS v3 score of 7.3 (HIGH), this vulnerability has a low attack complexity and can lead to low impact on confidentiality, integrity, and availability, particularly when combined with CVE-2015-6024 for arbitrary command execution. While no active exploitation is noted and community discussion is minimal, an ExploitDB entry exists, indicating public exploit code availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3g10wve-l101-s306ets-c01_r03CPE matchmatch criteria | cpe:2.3:o:netcommwireless:hspa_3g10wve_firmware:3g10wve-l101-s306ets-c01_r03:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.