vendor:
PLC Wireless Router GPN2.4P21-C-CN
by:
Kumar Saurav
8.8
CVSS
HIGH
Incorrect Access Control
287
CWE
Product Name: PLC Wireless Router GPN2.4P21-C-CN
Affected Version From: W2001EN-00
Affected Version To: W2001EN-00
Patch Exists: YES
Related CWE: CVE-2019-6279
CPE: h:chinamobile:plc_wireless_router_gpn2.4p21-c-cn
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
PLC Wireless Router GPN2.4P21-C-CN -Incorrect Access Control
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
Mitigation:
Ensure that access control policies are properly enforced and that only authorized users are allowed to access the system.