CVE-2019-6451

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
06/06/2019
Last modified:
28/02/2023

Description

On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:soyal:ar-727h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:soyal:ar-727h:-:*:*:*:*:*:*:*
cpe:2.3:o:soyal:ar-829ev5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:soyal:ar-829ev5:-:*:*:*:*:*:*:*