Advisories

Akuvox Smart Intercom S539 Improper Access Control via ServicesHTTPAPI

Go Back
severity
high
date
Affecting
  • Akuvox Smart Doorphone S539, S532, X916, X915, X912

  • Akuvox Smart Intercom R20K-2, R20A-2, C313W-2, NS-2, NC-2, NX-2

CWE
  • CWE-862 Missing Authorization
CVSS
8.7
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
Description
Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.