CVE-2022-40494

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
06/10/2022
Last modified:
17/04/2025

Description

NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ehang-io:nps:*:*:*:*:*:*:*:* 0.19.0 (including) 0.26.10 (including)