vendor:
PolyEco Digital FM Transmitter
by:
LiquidWorm
7.5
CVSS
HIGH
Authentication Bypass, Account Takeover/Lockout and Elevation of Privileges
287
CWE
Product Name: PolyEco Digital FM Transmitter
Affected Version From: PolyEco1000 CPU:2.0.6 FPGA:10.19
Affected Version To: PolyEco300 CPU:2.0.0 FPGA:10.19
Patch Exists: NO
Related CWE:
CPE: a:sielco_s.r.l:polyeco_digital_fm_transmitter
Platforms Tested: lwIP/2.1.1
2023
Sielco PolyEco Digital FM Transmitter 2.0.6 – Account Takeover / Lockout / EoP
The application suffers from an authentication bypass, account takeover/lockout and elevation of privileges vulnerability that can be triggered by directly calling the users object and effectively modifying the password of the two constants user/role (user/admin). This can be exploited by an unauthenticated adversary by issuing a single POST request to the vulnerable endpoint and gain unauthorized access to the affected device with administrative privileges.
Mitigation:
Ensure that authentication is properly implemented and enforced.