Back

MEDIUM

Sricam DeviceViewer 3.12.0.1 Password Change Security Bypass

Published Feb 20, 2026

Description

Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Feb 20, 2026
Updated Apr 7, 2026
Reserved Feb 19, 2026
CISA Vulnrichment
Updated Feb 24, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a