Skip to content

Latest commit

 

History

History
19 lines (14 loc) · 1023 Bytes

unauth_account_takeover.md

File metadata and controls

19 lines (14 loc) · 1023 Bytes

CVE-2022-47697

Vendor: COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd)

Firmware version: V2.3.0.1

Driver version: 4.1.0.0_CL15074

Vendor Fix: N/A

Impact: Unauth password change of root user account

Description: an unauthenticated user has the ability to reset the password of the admin user account


this endpoint can be accessed unauthed after a password has been set for the admin account/the device is initiated and running.

image

image

This will cause the device to reboot as you're forcing a change in the configuration

image