Descrição
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel. The attack may be initiated remotely. The attack-s complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used. The patch is named 017601354be38cb027ff3ffb01aed79bd5d12610. Applying a patch is the recommended action to fix this issue.
CVSS 5.6EPSS 0.393%Risco 0.58
Ver fonte- Publicação
- 2026-07-19 00:16:40
- Versões afetadas
- <=0.2.9
- Tipo
- Software crítico
- Última alteração
- 2026-07-21 15:16:32
- Vetor
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L