← Back to browse · API

CVE-2023-32645

Severity
CRITICAL
CVSS
9.8
EPSS
0.53812
Risk score
58.03
CISA KEV
No
PoC
No
Published
2023-10-11
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2023-36888, GHSA-H538-8M3C-JG9C
Products
Yifan:YF325 v1.0_20221108
Sources
euvd EUVD-2023-36888

Description

A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.

References