VYPR
High severity8.0NVD Advisory· Published Jun 18, 2021· Updated Jun 17, 2026

CVE-2021-23845

CVE-2021-23845

Description

This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which was released on June 2019.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:o:bosch:b426-cn_firmware:*:*:*:*:*:*:*:*
    Range: <03.08
  • cpe:2.3:o:bosch:b426-m_firmware:*:*:*:*:*:*:*:*
    Range: <03.10
  • cpe:2.3:o:bosch:b426_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:bosch:b426_firmware:*:*:*:*:*:*:*:*range: <03.08
    • (no CPE)range: unspecified
  • cpe:2.3:o:bosch:b429-cn_firmware:*:*:*:*:*:*:*:*
    Range: <03.08
  • Bosch/B426llm-fuzzy
    Range: before 3.08

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.