PT-2021-9472 · Depstech · Depstech Wifi Digital Microscope
Published
2021-07-15
·
Updated
2022-07-12
·
CVE-2020-12734
CVSS v2.0
4.8
Medium
| Vector | AV:A/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DEPSTECH WiFi Digital Microscope version 3
Description
The issue allows remote attackers to change the SSID and password of the device, potentially leading to a ransom demand from the rightful device owner. This is due to the lack of a reset option to Factory Default settings.
Recommendations
For DEPSTECH WiFi Digital Microscope version 3, consider restricting access to the device's configuration settings to prevent unauthorized changes to the SSID and password. As a temporary workaround, limit the device's exposure to the network to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Depstech Wifi Digital Microscope