rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. `Authorization: fake`) satisfies the guard, granting access to every endpoint protected only by this request guard.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | cve.org | 9.1 | — | — |
| 3.1 | Primary | cve.org | 9.1 | — | — |
| 3.1 | Secondary | ENISA EUVD | 9.1 | — | — |
| 3.1 | Secondary | NVD | 9.1 | 3.9 | 5.2 |