CVE-2019-6441
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.
Affected (5)
Products: Coship: Rt3050 Firmware, Rt3052 Firmware, Rt7620 Firmware, Wm3300 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0.0.40 |
| Running on/with | Platform Versions |
|---|---|
Coship Rt3050 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0.0.48 |
| Running on/with | Platform Versions |
|---|---|
Coship Rt3052 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0.0.49 |
| Running on/with | Platform Versions |
|---|---|
Coship Rt7620 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0.0.54 |
| Running on/with | Platform Versions |
|---|---|
Coship Wm3300 | All versions |
References (12)
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Timeline
No history available yet.