CVE-2023-41355 describes a critical input validation vulnerability in the Chunghwa Telecom NOKIA G-040W-Q firewall function. An unauthenticated remote attacker can exploit this flaw by sending specially crafted ICMP redirect messages to modify the device's network routing table. This can lead to a denial of service or the leakage of sensitive information, with a CVSS score of 9.8 (Critical) due to its network attack vector and low attack complexity. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
g040wqr201207CPE matchmatch criteria | cpe:2.3:o:nokia:g-040w-q_firmware:g040wqr201207:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.