PT-2024-5763 · Vonets · Vonets Industrial Wifi Bridge Relays+1

Wodzen

·

Published

2024-08-01

·

Updated

2024-08-20

·

CVE-2024-29082

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Vonets industrial wifi bridge relays and wifi bridge repeaters versions 3.3.23.6.9 and prior
Description The issue is related to improper access control, allowing an unauthenticated remote attacker to bypass authentication and factory reset the device via unprotected goform endpoints. This enables the attacker to reset the device to its factory settings, potentially leading to unauthorized access or control.
Recommendations For versions 3.3.23.6.9 and prior, consider disabling access to the goform endpoints as a temporary workaround until a patch is available. Restricting access to these endpoints can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-06476
CVE-2024-29082

Affected Products

Vonets Industrial Wifi Bridge Relays
Vonets Wifi Bridge Repeaters