PT-2026-7620 · Device · Device

Deepak Singh

+1

·

Publicado

2026-02-11

·

Atualizado

2026-02-16

·

CVE-2026-24789

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Affected versions not specified
Description An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication. The vulnerable API endpoint is exposed without requiring any form of authentication, enabling unauthorized password modifications. The password can be changed remotely via the API.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24789

Produtos afetados

Device