vendor:
PolyEco Digital FM Transmitter
by:
LiquidWorm
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: PolyEco Digital FM Transmitter
Affected Version From: 2.0.6
Affected Version To: 1.7.2000
Patch Exists: YES
Related CWE:
CPE: a:sielco:polyeco_digital_fm_transmitter
Platforms Tested: lwIP/2.1.1
2023
Sielco PolyEco Digital FM Transmitter 2.0.6 – Unauthenticated Information Disclosure
Sielco PolyEco is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this, via a specially crafted request to gain access to sensitive information.
Mitigation:
Enforce proper access control and authentication.