Unauthenticated User Friend Addition Vulnerability in Elf-G10HN 1.0.0.608

Unauthenticated User Friend Addition Vulnerability in Elf-G10HN 1.0.0.608

CVE-2021-22449 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to exploit this vulnerability. Due to insufficient security design, successful exploit could allow an attacker to add users to be friends without prompting in the target device.

Learn more about our User Device Pen Test.