CVE-2026-22312
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Exploitability: 3.9 / Impact: 4.7
Source: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 (Secondary)
Description
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration
and execute some commands (e.g. system reboot).
References (1)
Source: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
Timeline
No history available yet.