What the vulnerability does

01Description

The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.

Key dates

02Disclosure timeline

February 24, 2022 CVE published
April 17, 2025 Record updated