CVE-2017-20223
Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.3EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
16 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive information and access functionalities without proper access controls.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Telesquare · SDT-CS3B1Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://cxsecurity.com/issue/WLB-2017120297https://exchange.xforce.ibmcloud.com/vulnerabilities/136993https://packetstormsecurity.com/files/145551https://www.exploit-db.com/exploits/43402/https://www.vulncheck.com/advisories/telesquare-skt-lte-router-sdt-cs3b1-insecure-direct-object-referencehttps://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5445.php