Back

HIGH

eWON Firmware 12.2-13.0 Authentication Bypass via wsdReadForm

Published Mar 11, 2026

Description

eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitive user data by exploiting the wsdReadForm endpoint. Attackers can send POST requests to /wrcgi.bin/wsdReadForm with base64-encoded partial credentials and a crafted wsdList parameter to extract encrypted passwords for all users, which can be decrypted using a hardcoded XOR key.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Mar 11, 2026
Updated Jul 15, 2026
Reserved Feb 22, 2026

CISA Vulnrichment

Updated Mar 11, 2026

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Mar 11, 2026
Updated Jul 15, 2026

GitHub

No data