PT-2026-90820 · Vvbbnn00 · Warp-Clash-Api
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
vvbbnn00 WARP-Clash-API versions up to c7bf2360073959861219b422e51ae86411051b46
Description
A remote attack is possible due to missing authentication in the
authorized() function. This occurs when the SECRET KEY argument is manipulated. This issue affects products that are no longer supported by the maintainer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Warp-Clash-Api