PT-2022-22317 · Allnet · Allnet Router Wr0500Ac

Metadata

·

Published

2022-07-21

·

Updated

2023-08-08

·

CVE-2022-34767

CVSS v3.1

5.9

Medium

VectorAV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ALLNET Router model WR0500AC (affected versions not specified)
Description The web page "wizardpwd.asp" is prone to an authorization bypass issue, where the password located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin without validating the user's identity, making it accessible publicly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-34767

Affected Products

Allnet Router Wr0500Ac