Home 11.7 (custom)
affected
Description
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
Problem types
CWE-208 Observable Timing Discrepancy
Product status
References
gitlab.com/...a/-/blame/master/src/tomahawk.c?ref_type=heads