Loading
Generated remediation guidance and an executive summary. No account required.
eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitive user data by exploiting the wsdReadForm endpoint. Attackers can send POST requests to /wrcgi.bin/wsdReadForm with base64-encoded partial credentials and a crafted wsdList parameter to extract encrypted passwords for all users, which can be decrypted using a hardcoded XOR key.
No affected products information available.
Use CWE-798 to widen CVE-2019-25470 into its surrounding weakness, vendor, and product context.