CVE-2018-16591

FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
References
Link Resource
https://cyberskr.com/blog/furuno-felcom.html Exploit Technical Description Third Party Advisory
https://gist.github.com/CyberSKR/2c30d964d48b5e1518ded88bd953b710 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:furuno:felcom_250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:furuno:felcom_250:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:furuno:felcom_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:furuno:felcom_500:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-09-10 17:29

Updated : 2024-02-04 20:03


NVD link : CVE-2018-16591

Mitre link : CVE-2018-16591

CVE.ORG link : CVE-2018-16591


JSON object : View

Products Affected

furuno

  • felcom_500_firmware
  • felcom_250
  • felcom_250_firmware
  • felcom_500
CWE
CWE-862

Missing Authorization