Extreme Networks ExtremeGuest Essentials Captive Portal Brute Force Vulnerability
Vulnerability
A vulnerability in ExtremeGuest Essentials versions prior to 25.5.0 allows unauthorized access through a manual brute-force attack on the captive portal. In certain SSID configurations, repeated login attempts can trick the system into marking an unauthenticated device as authenticated, granting it network access. Notably, Client360 logs may incorrectly display the client's MAC address as the username, even though MAC authentication is not enabled.
Impact
Exploitation of this vulnerability could lead to unauthorized network access.
Remediation
Users can upgrade to ExtremeGuest Essentials version 25.5.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
