R Radio Network FM Transmitter Password Disclosure Vulnerability in System.cgi Endpoint

Vulnerability

A vulnerability in R Radio Network FM Transmitter version 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint. This improper access control enables authentication bypass and unauthorized access to FM station setup parameters.

Impact

Exploitation of this vulnerability leads to unauthorized access to the admin password, allowing attackers to bypass authentication and manipulate FM station settings.

Reproduction

To reproduce this vulnerability, send a request to the system.cgi endpoint on the affected device. The response will include the clear-text password for the admin user, which can then be used to bypass authentication and access the FM station setup.

Remediation

Users can upgrade to R Radio Network FM Transmitter version 1.09 to address this vulnerability.

Added: Dec 4, 2025, 9:29 PM
Updated: Dec 4, 2025, 9:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
7.7
relevance
1.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.