Threat Labs · CVE Advisory
CVE-2023-24738criticalAuthentication Bypass

Authentication Bypass in Araknis Networks (Control4) Network Router

A weak password reset mechanism in Araknis Networks routers allows an attacker to manipulate HTTP requests or client-side code to bypass authentication and reset device credentials — gaining full control of the router and the network it manages.

Technical Analysis

The vulnerability involves insecure restrictions on the password reset form in the web management interface. Attackers can use crafted in-browser code manipulation to alter client-side validation and submit password reset requests that the router incorrectly fulfills.

Impact

Full administrative control of the network router, including firewall rules, routing configuration, DNS settings, and connected device visibility.

Affected Versions
  • AN-310-RT-4L2W — all versions prior to v1.1.66
  • AN-110-RT-2L1W — all versions prior to v1.0.88
  • AN-110-RT-2L1W-WIFI — all versions prior to v1.0.88
Disclosure Timeline
December 20, 2022Discovered by Redinent researchers
December 29, 2022Reported to CERT India
January 20, 2023OEM acknowledgment from Araknis / Control4
May 30, 2023CVE assigned; vendor released patched firmware
CVE ID
CVE-2023-24738
Vendor
Araknis Networks (Control4)
Product
AN-310-RT and AN-110-RT Router Series
Category
Network Router
Vulnerability Type
Authentication Bypass
Severity
CRITICAL
Published
June 21, 2023
Researcher
Redinent Threat Labs, reported via CERT India
External Advisory
Vendor Release Notes
Redinent Vikron

Vikron detects this class of
vulnerability automatically.

Redinent Vikron's firmware-level analysis identifies authentication bypass patterns across your entire device fleet — without manual testing.