CVE-2019-7564
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
07/05/2019
Last modified:
24/08/2020
Description
An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:coship:rt3052_firmware:4.0.0.48:*:*:*:*:*:*:* | ||
| cpe:2.3:h:coship:rt3052:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:coship:rt3050_firmware:4.0.0.40:*:*:*:*:*:*:* | ||
| cpe:2.3:h:coship:rt3050:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:coship:wm3300_firmware:5.0.0.54:*:*:*:*:*:*:* | ||
| cpe:2.3:o:coship:wm3300_firmware:5.0.0.55:*:*:*:*:*:*:* | ||
| cpe:2.3:h:coship:wm3300:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:coship:rt7620_firmware:10.0.0.49:*:*:*:*:*:*:* | ||
| cpe:2.3:h:coship:rt7620:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



