vendor:
WDTV Live SMP
by:
sw1tch
7,5
CVSS
HIGH
Remote Password Reset
287
CWE
Product Name: WDTV Live SMP
Affected Version From: 2.03.20
Affected Version To: 2.03.20
Patch Exists: NO
Related CWE: None
CPE: h:western_digital:wdtv_live_smp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
WDTV Live SMP Remote Password Reset Vulnerability
An unauthenticated attacker can update the password via a constructed GET request, subsequently taking control of many functions of the device. Vulnerable versions include at least firmware 2.03.20, and likely many more older versions.
Mitigation:
None available. Device appears to be EOL so unlikely to be remediated.