CVE-2002-0396 describes a critical authentication bypass vulnerability in the Red-M 1050 Bluetooth Access Point's web management server. This flaw allows unauthorized attackers to gain access by connecting from the same IP address as an already authenticated user, as the server lacks proper session-based credential validation. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing for network-based attacks with low complexity that can lead to partial compromise of confidentiality, integrity, and availability. The FAUCET Risk Score of 85/100 further emphasizes its significant risk. While there is no evidence of active exploitation, nor readily available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered notable community discussion with 10 mentions, indicating awareness and potential interest among researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:red-m:1050ap_lan_acess_point:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.