Cubro EXA48200 Web GUI Privilege Escalation Vulnerability

Vulnerability

A broken access control vulnerability has been identified in the web GUI of the Cubro EXA48200 network packet broker, specifically in build 20231025055018. This vulnerability allows remote authenticated users to escalate their privileges to administrator level by sending an HTTP PUT request to the API endpoint used for password changes. The request must include the 'rolename' attribute set to 'Administrator'.

Impact

Exploiting this vulnerability grants users full administrative rights, including the ability to change passwords for all other user accounts, thereby compromising the entire web application.

Reproduction

To reproduce this vulnerability, first log in as a user with low privileges. Then, send an HTTP PUT request to the '/api/user/users' endpoint. Include the 'rolename' attribute in the request body, setting it to 'Administrator'. After the request is processed, the user will gain administrative privileges, as evidenced by the availability of administrative functions in the user interface.

Remediation

Users are advised to update to Cubro EXA48200 Firmware Version V5.0R14.5P4-V3.3R1, where this vulnerability has been patched.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.