vendor:
PolyEco Digital FM Transmitter
by:
LiquidWorm
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: PolyEco Digital FM Transmitter
Affected Version From: PolyEco1000 CPU:2.0.6 FPGA:10.19
Affected Version To: PolyEco300 CPU:2.0.0 FPGA:10.19
Patch Exists: NO
Related CWE:
CPE: a:sielco_s.r.l:polyeco_digital_fm_transmitter
Platforms Tested: lwIP/2.1.1
2020
Sielco PolyEco Digital FM Transmitter 2.0.6 – Authentication Bypass Exploit
The application suffers from an authentication bypass and account takeover/lockout vulnerability that can be triggered by directly calling the users object and effectively modifying the password of the two constants user/role (user/admin). This can be exploited by an unauthenticated adversary by issuing a single POST request to the vulnerable endpoint and gain unauthorized access to the affected device with administrative privileges.
Mitigation:
Enforce strong authentication and authorization policies, and ensure that all user accounts are properly secured.