Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppm2-7rr7-h984

Опубликовано: 19 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.

EPSS

Процентиль: 44%
0.0022
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.

EPSS

Процентиль: 44%
0.0022
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287