10

CVE-2019-6441

Exploit
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Coship ≫ Rt3050 Firmware Version 4.0.0.40
   Coship ≫ Rt3050 Version -
Coship ≫ Rt3052 Firmware Version 4.0.0.48
   Coship ≫ Rt3052 Version -
Coship ≫ Rt7620 Firmware Version 10.0.0.49
   Coship ≫ Rt7620 Version -
Coship ≫ Wm3300 Firmware Version 5.0.0.54
   Coship ≫ Wm3300 Version -
Coship ≫ Wm3300 Firmware Version 5.0.0.55
   Coship ≫ Wm3300 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 53.61% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://packetstormsecurity.com/files/151202/Coship-Wireless-Router-Unauthenticated-Admin-Password-Reset.html
Third Party Advisory
Exploit
VDB Entry
https://packetstormsecurity.com/files/151202/Coship-Wireless-Router-Unauthenticated-Admin-Password-Reset.html
Third Party Advisory
Exploit
VDB Entry
https://vulmon.com/exploitdetails?qidtp=EDB&qid=46180
Third Party Advisory
Exploit
https://www.anquanke.com/vul/id/1451446
Third Party Advisory
Exploit
https://www.exploit-db.com/exploits/46180
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/46180/
Third Party Advisory
Exploit
VDB Entry