10
CVSSv2

CVE-2019-12254

Published: 06/05/2022 Updated: 16/05/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gok smartbox_4_lan_firmware

gok smartbox_4_lan_pro_firmware

tecson lx-q-net_firmware

tecson lx-net_firmware

tecson e-litro_net_firmware