vendor:
SKT LTE Wi-Fi SDT-CW3B1
by:
Safak Aslan
7.5
CVSS
HIGH
Unauthorized Admin Credential Change
798
CWE
Product Name: SKT LTE Wi-Fi SDT-CW3B1
Affected Version From: SKT CW3B1 sw version 1.2.0
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:telesquare:skt_lte_wifi_sdt-cw3b1
Platforms Tested: Windows
2018
SKT LTE Wi-Fi SDT-CW3B1 – Unauthorized Admin Credential Change
Using the directory of /admin/management.shtml, it is possible to access directly System Management without authentication. The attacker has the right to change User ID, Password for General User, User ID, and Password for Admin.
Mitigation:
The vendor should implement proper authentication mechanisms for accessing the System Management interface.