Positron Broadcast Signal Processor...

- AV AC AU C I A
发布: 2024-04-04
修订: 2025-04-13

The Positron Broadcast Digital Signal Processor TRA7005 version 1.20 suffers from an authentication bypass through a direct and unauthorized access to the password management functionality. The vulnerability allows attackers to bypass Digest authentication by manipulating the password endpoint _Passwd.html and its payload data to set a user's password to arbitrary value or remove it entirely. This grants unauthorized access to protected areas (/user, /operator, /admin) of the application without requiring valid credentials, compromising the device's system security.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息