vendor:
01dB CUBE Smart Noise Monitoring Terminal
by:
Todor Donev
8,8
CVSS
HIGH
Remote Password Change
287
CWE
Product Name: 01dB CUBE Smart Noise Monitoring Terminal
Affected Version From: 2.34
Affected Version To: 2.10
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Acoem 01dB CUBE Smart Noise Monitoring Terminal Remote Password Change
A vulnerability in Acoem 01dB CUBE Smart Noise Monitoring Terminal allows an attacker to remotely change the password of the device. This vulnerability exists due to the lack of authentication when sending a GET request to the F_validPassword.asp page with the new password as a parameter. This allows an attacker to gain access to the device without knowing the current password.
Mitigation:
Authentication should be enforced when sending requests to the F_validPassword.asp page.