CVE-2023-45598
Description
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A forced browsing vulnerability in AiLux imx6 bundle's measure functionality allows unauthenticated remote attackers to access confidential measurement data.
Vulnerability
A CWE-425 Direct Request ('Forced Browsing') vulnerability exists in the "measure" functionality of the AiLux imx6 bundle web application. The application fails to enforce proper access controls on specific URLs, allowing an unauthenticated remote attacker to directly request and retrieve confidential measure information. This issue affects all imx6 bundle versions below imx6_1.0.7-2. [1]
Exploitation
An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable endpoint without any authentication. No special network position, user interaction, or prior knowledge is required; the attacker only needs network access to the device. The forced browsing attack directly accesses the measure functionality URLs that lack proper access controls. [1]
Impact
Successful exploitation allows the attacker to read confidential measure information from the device. The impact is limited to information disclosure (confidentiality) with low severity (CVSS 5.3). No integrity or availability impact is reported. The attacker gains no further privileges beyond accessing the measure data. [1]
Mitigation
The vulnerability is fixed in imx6 bundle version imx6_1.0.7-2. Users should update to this version or later. No workarounds are mentioned in the advisory. The CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: < imx6_1.0.7-2
- AiLux/imx6 bundlev5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.