Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| G-040w-q_firmware | Nokia | g040wqr201207 (including) | g040wqr201207 (including) |