CVE-2018-16591

FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
References
Link Resource
https://cyberskr.com/blog/furuno-felcom.html Exploit Technical Description Third Party Advisory
https://gist.github.com/CyberSKR/2c30d964d48b5e1518ded88bd953b710 Third Party Advisory
https://cyberskr.com/blog/furuno-felcom.html Exploit Technical Description Third Party Advisory
https://gist.github.com/CyberSKR/2c30d964d48b5e1518ded88bd953b710 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:furuno:felcom_250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:furuno:felcom_250:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:furuno:felcom_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:furuno:felcom_500:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:53

Type Values Removed Values Added
References () https://cyberskr.com/blog/furuno-felcom.html - Exploit, Technical Description, Third Party Advisory () https://cyberskr.com/blog/furuno-felcom.html - Exploit, Technical Description, Third Party Advisory
References () https://gist.github.com/CyberSKR/2c30d964d48b5e1518ded88bd953b710 - Third Party Advisory () https://gist.github.com/CyberSKR/2c30d964d48b5e1518ded88bd953b710 - Third Party Advisory

Information

Published : 2018-09-10 17:29

Updated : 2024-11-21 03:53


NVD link : CVE-2018-16591

Mitre link : CVE-2018-16591

CVE.ORG link : CVE-2018-16591


JSON object : View

Products Affected

furuno

  • felcom_500_firmware
  • felcom_250
  • felcom_250_firmware
  • felcom_500
CWE
CWE-862

Missing Authorization