COMMAX Smart Home System Unauthenticated Configuration Change and Denial-of-Service Vulnerability

Vulnerability

A vulnerability in the COMMAX Smart Home System's CCTV Bridge DVR Service allows an unauthenticated attacker to change configuration settings and cause a denial-of-service condition. This is achieved by sending a malformed request to the 'setconf' endpoint, which is responsible for handling configuration changes. The vulnerability arises from missing authentication for critical functions, enabling unauthorized users to manipulate device settings and disrupt service availability.

Impact

Exploitation of this vulnerability leads to unauthorized configuration changes and a denial-of-service condition, where the device becomes unresponsive or unavailable.

Reproduction

The vulnerability can be reproduced by sending a POST request to the 'setconf' endpoint with specific data parameters. This request can be made using tools like curl. The data should include configuration values that, when processed by the endpoint, trigger the denial-of-service condition. After the request is sent, the server responds with a confirmation message, but the connection to the 'setconf' endpoint is subsequently refused, indicating a successful denial-of-service attack.

Added: Dec 9, 2025, 9:56 PM
Updated: Dec 9, 2025, 9:56 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
8.7
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.