vendor:
Analog FM Transmitter
by:
LiquidWorm
7.5
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Analog FM Transmitter
Affected Version From: 2.12 (EXC5000GX)
Affected Version To: 1.5.4 (EXC120GT)
Patch Exists: YES
Related CWE:
CPE: a:sielco:analog_fm_transmitter
Platforms Tested: lwIP/2.1.1, Web/3.0.3
2023
Sielco Analog FM Transmitter 2.12 – Remote Privilege Escalation
The application suffers from a privilege escalation vulnerability. A user with Read permissions can elevate his/her privileges by sending a HTTP POST request setting the parameter 'auth1' or 'auth2' or 'auth3' to integer value '1' for Write or '2' for Admin permissions.
Mitigation:
Ensure that users are only granted the minimum privileges necessary to perform their job functions.