VULNERABILITY INTELLIGENCE

CVE-2012-4669

CVSS score5.8 MEDIUM
EPSS probability0.88%
CISA KEVNot currently listed
Published2012-08-25
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:P/I:P/A:N

Description

M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted.

Weakness classification

  • CWE-20: Improper Input Validation

Primary references