vendor:
Smart Home
by:
Z3ro0ne
7.5
CVSS
HIGH
Unauthorized Password Reset
287
CWE
Product Name: Smart Home
Affected Version From: 4.15
Affected Version To: 4.15
Patch Exists: NO
Related CWE: None
CPE: a:contec:smart_home
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Google Chrome
2018
Contec smart home 4.15 Unauthorized Password Reset
The vulnerability allows an unauthenticated attacker to remotely bypass authentication and change the admin password without the old password and control (lamps, doors, air conditioners, etc.).
Mitigation:
Ensure that authentication is properly implemented and enforced.