vendor:
PolyEco Digital FM Transmitter
by:
LiquidWorm
5.5
CVSS
MEDIUM
Improper Access Control
287
CWE
Product Name: PolyEco Digital FM Transmitter
Affected Version From: PolyEco1000 CPU:2.0.6 FPGA:10.19
Affected Version To: PolyEco300 CPU:2.0.0 FPGA:10.19
Patch Exists: NO
Related CWE:
CPE: a:sielco_s.r.l:polyeco_digital_fm_transmitter
Platforms Tested: lwIP/2.1.1
2023
Sielco PolyEco Digital FM Transmitter 2.0.6 – Radio Data System POST Manipulation
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions and manipulate the RDS text display.
Mitigation:
Implement proper access control checks to verify the requests.