PT-2026-24768 · Ewon · Ewon

·

CVE-2019-25470

·

Published

2026-03-11

·

Updated

2026-03-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions eWON versions 12.2 through 13.0
Description eWON firmware contains an authentication bypass that allows attackers with minimal privileges to retrieve sensitive user data. Attackers can exploit the wsdReadForm API endpoint by sending POST requests to /wrcgi.bin/wsdReadForm with base64-encoded partial credentials and a crafted wsdList parameter. This allows extraction of encrypted passwords for all users, which can be decrypted using a hardcoded XOR key.
Recommendations Versions 12.2 through 13.0 should be updated when a fix becomes available. As a temporary workaround, restrict access to the wsdReadForm endpoint.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25470

Affected Products

Ewon