7.5
CVSSv2

CVE-2019-7564

Published: 07/05/2019 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

coship rt3052_firmware 4.0.0.48

coship rt3050_firmware 4.0.0.40

coship wm3300_firmware 5.0.0.54

coship wm3300_firmware 5.0.0.55

coship rt7620_firmware 10.0.0.49

Exploits

Coship Wireless Router versions 400x and 500x suffer from an unauthenticated password reset vulnerability ...