CVE-2026-102245 SurfSense 缺失认证漏洞
影响攻击者可绕过认证访问受保护的接口功能
MODSetter SurfSense 2.0.3 及之前版本的 circleback webhook 路由存在认证缺失问题。该漏洞位于 surfsense_backend/app/routes/circleback_webhook_route.py 文件中的未知函数,攻击者可远程利用。漏洞利用代码已公开,厂商未作回应。
影响范围
MODSetter SurfSense 2.0.3 及更早版本。
漏洞详情
该漏洞属于认证缺失(Missing Authentication)类型,circleback webhook 端点未对请求进行身份验证。远程攻击者可直接向该接口发送请求,无需任何凭据即可触发受保护的功能。由于利用方式已公开,攻击门槛较低。
利用条件与风险
攻击者可远程发起利用,无需认证即可访问相关接口,实战风险较高;具体可造成的业务影响取决于该端点所暴露的功能。
修复建议
暂无官方修复方案,厂商未回应。建议在网关或反向代理层对该 webhook 端点实施访问控制与来源校验,或暂时禁用该路由。
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.