CVE-2019-6441

UnknownEPSS 53.61%

Last modified

CVE-2019-6441 is a vulnerability of currently unknown severity. An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. EPSS estimates a 53.61% chance of exploitation in the next 30 days.

Description

An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.

Metrics

EPSS Probability
53.61%

98.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CoshipRt3050 Firmware4.0.0.40
CoshipRt3052 Firmware4.0.0.48
CoshipRt7620 Firmware10.0.0.49
CoshipWm3300 Firmware5.0.0.54
CoshipWm3300 Firmware5.0.0.55

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-6441?
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.
How severe is CVE-2019-6441?
Severity scoring for CVE-2019-6441 is pending analysis. The EPSS model estimates a 53.61% probability of exploitation in the next 30 days.
How do I fix CVE-2019-6441?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-6441?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST