PT-2021-9472 · Depstech · Depstech Wifi Digital Microscope

Published

2021-07-15

·

Updated

2022-07-12

·

CVE-2020-12734

CVSS v2.0

4.8

Medium

VectorAV:A/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions DEPSTECH WiFi Digital Microscope version 3
Description The issue allows remote attackers to change the SSID and password of the device, potentially leading to a ransom demand from the rightful device owner. This is due to the lack of a reset option to Factory Default settings.
Recommendations For DEPSTECH WiFi Digital Microscope version 3, consider restricting access to the device's configuration settings to prevent unauthorized changes to the SSID and password. As a temporary workaround, limit the device's exposure to the network to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12734

Affected Products

Depstech Wifi Digital Microscope