CVE-2018-16591

FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
References
Link Resource
https://gist.github.com/CyberSKR/2c30d964d48b5e1518ded88bd953b710 Third Party Advisory
https://cyberskr.com/blog/furuno-felcom.html Exploit Technical Description Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:furuno:felcom_250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:furuno:felcom_250:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:furuno:felcom_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:furuno:felcom_500:-:*:*:*:*:*:*:*

Information

Published : 2018-09-10 10:29

Updated : 2020-08-24 10:37


NVD link : CVE-2018-16591

Mitre link : CVE-2018-16591


JSON object : View

CWE
CWE-862

Missing Authorization

Advertisement

dedicated server usa

Products Affected

furuno

  • felcom_250
  • felcom_500
  • felcom_500_firmware
  • felcom_250_firmware