CVE-2023-41353 describes a weak password requirement vulnerability in Chunghwa Telecom NOKIA G-040W-Q devices, affecting both the hardware and its firmware. This vulnerability carries a high CVSS score of 8.8, indicating that a remote attacker with regular user privileges can easily infer the administrator password, leading to full administrative access and potential disruption of service. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
g040wqr201207CPE matchmatch criteria | cpe:2.3:o:nokia:g-040w-q_firmware:g040wqr201207:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.