DB Elettronica Telecomunicazioni SFT DAB 600/C
cpe:2.3:h:dbbroadcast:sft_dab_600/c:*:*:*:*:*:*:*, +3 more
- 1.9.3
- 7.1 (Apr 19 2021)
- 2.46
- 169.55
- 6.15
An authentication bypass vulnerability has been identified in the Screen SFT DAB digital audio broadcasting transmitter, specifically in version 1.9.3. This vulnerability allows attackers to change the admin password without needing the current password. Exploitation involves sending a crafted JSON request with a new password hashed using MD5 to the userManager.cgx endpoint, directly modifying the admin account.
Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to unauthorized administrative access.
To reproduce this vulnerability, send a POST request to the userManager.cgx endpoint with a JSON payload that includes the 'username' set to 'admin' and the 'password' set to the desired new password, hashed with MD5. Include the appropriate headers to mimic a request from the transmitter's web interface.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.