PT-2024-14280 · Skyworth · Skyworth Router Cm5100

Dr. Faruk Kazi

+3

·

Published

2024-01-17

·

Updated

2024-01-20

·

CVE-2023-51741

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Skyworth Router CM5100 version 4.1.1.24
Description This issue exists due to the transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this by eavesdropping on the victim’s network traffic to extract the username and password from the web interface, specifically the Password Reset Page, of the targeted system.
Recommendations For Skyworth Router CM5100 version 4.1.1.24, consider disabling the Password Reset Page functionality until a patch is available to prevent exploitation. Restrict access to the web interface to minimize the risk of eavesdropping and credential extraction.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51741

Affected Products

Skyworth Router Cm5100