vendor:
Reble610
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Reble610
Affected Version From: 0.01 Revision 0
Affected Version To: Not specified
Patch Exists: NO
Related CWE:
CPE: h:elber:reble610
Platforms Tested: NBFM Controller, embOS/IP
Not specified
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Authentication Bypass
The Elber Reble610 device is vulnerable to an authentication bypass issue that allows attackers to gain unauthorized and administrative access to protected areas of the application. This vulnerability occurs due to a flaw in the password management functionality, specifically in the set_pwd endpoint, which can be manipulated by attackers to overwrite the password of any user within the system.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input validation and access controls. Additionally, users should update to a patched version of the software if available.