Security Advisory

CVE-2022-34767

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-07-21 15:37:00
Last updated 2024-08-03 09:22:10
Assigner INCD
CVSS score 5.9
State PUBLISHED

Description

Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly.