On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.
References
| Link | Resource |
|---|---|
| http://www.nccst.nat.gov.tw | Broken Link Third Party Advisory |
| http://www.soyal.com/epaper/e-paper-en-117.html | Broken Link |
| https://github.com/cvereveal/CVEs/tree/master/CVE-2019-6451 | Exploit Third Party Advisory |
| https://www.soyal.com.tw/cve-2019-6451/ | Vendor Advisory |
| https://www.soyal.com/exhibition/cve-2019-6451/ | Broken Link |
| http://www.nccst.nat.gov.tw | Broken Link Third Party Advisory |
| http://www.soyal.com/epaper/e-paper-en-117.html | Broken Link |
| https://github.com/cvereveal/CVEs/tree/master/CVE-2019-6451 | Exploit Third Party Advisory |
| https://www.soyal.com.tw/cve-2019-6451/ | Vendor Advisory |
| https://www.soyal.com/exhibition/cve-2019-6451/ | Broken Link |
Configurations
History
21 Nov 2024, 04:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.nccst.nat.gov.tw - Broken Link, Third Party Advisory | |
| References | () http://www.soyal.com/epaper/e-paper-en-117.html - Broken Link | |
| References | () https://github.com/cvereveal/CVEs/tree/master/CVE-2019-6451 - Exploit, Third Party Advisory | |
| References | () https://www.soyal.com.tw/cve-2019-6451/ - Vendor Advisory | |
| References | () https://www.soyal.com/exhibition/cve-2019-6451/ - Broken Link |
28 Feb 2023, 20:47
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) http://www.nccst.nat.gov.tw - Broken Link, Third Party Advisory | |
| References | (MISC) https://www.soyal.com.tw/cve-2019-6451/ - Vendor Advisory | |
| References | (MISC) https://www.soyal.com/exhibition/cve-2019-6451/ - Broken Link | |
| References | (MISC) http://www.soyal.com/epaper/e-paper-en-117.html - Broken Link |
Information
Published : 2019-06-06 19:29
Updated : 2024-11-21 04:46
NVD link : CVE-2019-6451
Mitre link : CVE-2019-6451
CVE.ORG link : CVE-2019-6451
JSON object : View
Products Affected
soyal
- ar-829ev5_firmware
- ar-727h
- ar-727h_firmware
- ar-829ev5
CWE
CWE-306
Missing Authentication for Critical Function
