Back

CRITICAL

ALLNET Gmbh - ADSL/VDSL Router inkl. Modem and Wlan Authorization Bypass

Published Jul 21, 2022

Description

Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly.

Affected products

Remediation

Vendor solution

Update to the latest version.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner INCD
Published Jul 21, 2022
Updated Aug 3, 2024
Reserved Jun 29, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner INCD
Published Jul 21, 2022
Updated Aug 3, 2024

GitHub

No data