top | item 18673638

Logitech: “Options” Craft WebSocket server has no authentication

6 points| diafygi | 7 years ago |bugs.chromium.org

3 comments

order
[+] markovbot|7 years ago|reply
Does this pattern of vulnerability have a name? Where a piece of software listens on localhost but can be exploited by any webpage?
[+] border43|7 years ago|reply
This is ridiculous. This is why I hate installed third party software on my computer.

Thank you. I have blocked all incoming traffic on that port.

[+] markovbot|7 years ago|reply
I'd be much more concerned about traffic from localhost (from malicious web pages)