Unauth Admin Reset Password on AC Smart II
58Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 7.1epss 0.5%
de la publicación al arma
Publicada en NVD14 sept
VulnCheck+108d
probabilidad de explotación
0.5%top 63% de las CVE
explotación observada
síVulnCheck
A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetting the administrator password. The attacker can manipulate the page using developer tools to display and use the form. This form allows you to change the administrator password without verifying login status or user permissions.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
LG Electronics · AC Smart IIReferencias
https://lgsecurity.lge.com/bulletins