R Radio Network FM Transmitter Password Disclosure Vulnerability in System.cgi Endpoint
Vulnerability
A vulnerability in R Radio Network FM Transmitter version 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint. This improper access control enables authentication bypass and unauthorized access to FM station setup parameters.
Impact
Exploitation of this vulnerability leads to unauthorized access to the admin password, allowing attackers to bypass authentication and manipulate FM station settings.
Reproduction
To reproduce this vulnerability, send a request to the system.cgi endpoint on the affected device. The response will include the clear-text password for the admin user, which can then be used to bypass authentication and access the FM station setup.
Remediation
Users can upgrade to R Radio Network FM Transmitter version 1.09 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
