CVE-2022-47700

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
31/01/2023
Last modified:
27/03/2025

Description

COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect Access Control. Improper authentication allows requests to be made to back-end scripts without a valid session or authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:comfast_project:cf-wr623n_firmware:*:*:*:*:*:*:*:* 2.3.0.1 (including)
cpe:2.3:h:comfast_project:cf-wr623n:-:*:*:*:*:*:*:*