Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.gov.il/en/Departments/faq/cve_advisories | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2022-07-21 09:15
Updated : 2022-07-27 15:31
NVD link : CVE-2022-34767
Mitre link : CVE-2022-34767
JSON object : View
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
Products Affected
                allnet
- all-wr0500ac_firmware
 - all-wr0500ac
 


