ZeroHour

CVE-2025-28371

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p40
Published
()
Modified
Description

EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.

Vendors
engeniustech
Products
enh500 firmware
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.