vendor:
IMPACT/FIRST/PULSE/Eco v2.x
by:
LiquidWorm
8.8
CVSS
HIGH
Unauthenticated Factory Reset
306
CWE
Product Name: IMPACT/FIRST/PULSE/Eco v2.x
Affected Version From: Impact/Pulse/First (Version 2: 1.1/2.15)
Affected Version To: WM2 (Kantar Media) 1.11
Patch Exists: No
Related CWE:
CPE: h:sound4:impact_pulse_first_v2
Platforms Tested:
2020
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x – Unauthenticated Factory Reset
SOUND4 Ltd. devices are vulnerable to an unauthenticated factory reset. By visiting the unprotected /usr/cgi-bin/restorefactory.cgi endpoint and making a POST request, the device will immediately reset itself and all settings will be lost.
Mitigation:
Users should ensure that the /usr/cgi-bin/restorefactory.cgi endpoint is not accessible from the internet.