CVE-2023-53775
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.
Vendor
Product
CWE
Yayın Tarihi
2025-12-10 22:16:18
Güncelleme
2026-01-02 13:51:51
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-
Kategoriler
Referanslar
https://www.dbbroadcast.com
https://www.dbbroadcast.com/products/radio/sft-dab-series-compact-air/
https://www.exploit-db.com/exploits/51456
https://www.screen.it
https://www.vulncheck.com/advisories/screen-sft-dab-authentication-bypass-via-user-password-change
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5772.php
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5772.php