ZeroHour

CVE-2019-7564

PoC
CVSS 3.0
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.

Vendors
coship
Products
rt3052 firmware, rt3050 firmware, wm3300 firmware, rt7620 firmware
Weakness
CWE-306
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.