PoC Index

CVE-2023-33754

MEDIUM 6.5EPSS 0.7%

The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.66% chance of exploitation in the next 30 days, 49th percentile
Published
2023-06-01
Updated
2025-01-09

Proof-of-concept exploits (1)

References

Related