vendor:
DT-R002 2CH Smart Relay
by:
Victor Hanna (Trustwave SpiderLabs)
5.9
CVSS
MEDIUM
Authentication Bypass
294
CWE
Product Name: DT-R002 2CH Smart Relay
Affected Version From: V3.1.276A
Affected Version To: V3.1.276A
Patch Exists: NO
Related CWE: CVE-2022-29593
CPE: h:dingtian-tech:dt-r002_2ch_smart_relay
Platforms Tested: MAC OSX
2022
Dingtian-DT-R002 3.1.276A – Authentication Bypass
DingTian DT-R002 2CH Smart Relay is vulnerable to Authentication Bypass by Capture-replay. An attacker can send a crafted request to the vulnerable device to bypass authentication and gain access to the device.
Mitigation:
Ensure that authentication is properly implemented and enforced on the device.