An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.
7.2high severity
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
15/04/2022
Operating Systems1
Mw
Mwid25-Ds Firmware
by Fantec
1 Version
2 years ago
Vulnerability Categories1
Reliance on Cookies without Validation and Integrity Checking
http://www.vicarius.io
is owned and operated by Vicarius Ltd. (the “Company”). All information contained on the
Website is purely for informational, and educational purposes and should be independently
verified and confirmed. Vicarius does not accept any liability for any loss or damage
whatsoever caused in reliance upon such information or services. No statements or information
presented in any form by Vicarius is intended as fact, and you agree that you will not
consider the statements or information presented on the Website as fact or as a guarantee of
performance.
Related CVEs
Security Research Topics
By Vicarius Cartoons
Apr 12, 2023
Vicarius Cartoons Presents: IT Passover
By David Parkinson Frost
Mar 27, 2023
Acropalypse wreaking havoc, zero-days in Samsung Exynos, Emotet returns (again)
By Vicarius Cartoons
Feb 14, 2023
Vicarius Cartoons Presents: Cupid's Exploit
By Paul Lighter
Jan 11, 2023
When the Target is Also the Threat
A software failure grounded thousands of flights today, raising a complicated question - how do you secure an unstable system? The answer has never been more urgent.
By Paul Lighter
Jan 06, 2023
The Uncomfortable Implications of the LastPass Attack
The recent attack on LastPass has people questioning if they can trust password managers. But there's a bigger issue lurking underneath - can you trust ANY security vendor?