CVE-2022-34767

Publication date

2022-07-21 15:37:00

Family

INCD

State

PUBLISHED

Description

Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the users identity and can be accessed publicly.