CWE-293Variant

Using Referer Field for Authentication

Draft in the CWE catalog · 1 CVE mapped

1
CVEs mapped
9.0
Median CVSS
What it is

The referer field in HTTP requests can be easily modified and, as such, is not a valid means of message integrity checking.

Recent examples
9.0cvss
CVE-2023-20025

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated, remote…

🚨 A crafty HTTP request could let attackers waltz right past your router's login! This vulnerability in Cisco's web management interface is a game-changer for RV016, RV042, RV042G, and RV082 routers. 🔥 Think of it like someone slipping through the check-in desk at a hotel without a reservation — the front desk staff doesn’t realize the guest hasn’t been registered, so they gain access to all the facilities! This flaw allows an attacker to bypass authentication and get root access as if they were a legitimate user. If exploited, this vulnerability could allow an attacker to gain full control over your router, which means they could alter settings, intercept network traffic, or even launch attacks on other devices in your network. The potential for chaos is absolutely devastating!

CRITICAL
2%
epss
The record
Technical detail
CWE ID
CWE-293
Abstraction
Variant
Structure
Simple
Status
Draft
References (1)