CVE Feed

    Dashboard / CVE / CVE-2019-6441

    CVE-2019-6441

    An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.

    Published:Mar 19, 2019
    Last Modified:Nov 21, 2024
    EPS:Mar 19, 2019
    EPSS Score:0.46262
    CVSS Score:9.8

    Affected Products

    Vendor
    Coship
    Product
    Rt3050
    Vendor
    Coship
    Product
    Rt3050 Firmware
    Vendor
    Coship
    Product
    Rt3052
    Vendor
    Coship
    Product
    Rt3052 Firmware
    Vendor
    Coship
    Product
    Rt7620
    Vendor
    Coship
    Product
    Rt7620 Firmware
    Vendor
    Coship
    Product
    Wm3300
    Vendor
    Coship
    Product
    Wm3300 Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High