Back

HIGH

Electrolink FM/DAB/TV Transmitter Authentication Bypass by Assumed-Immutable Data

Published Apr 18, 2024

Description

Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access.

Affected products

Remediation

Vendor solution

Electrolink has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of the affected products are encouraged to contact Electrolink https://electrolink.com/contacts/ for additional information.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Apr 18, 2024
Updated Aug 1, 2024
Reserved Apr 12, 2024

CISA Vulnrichment

Updated Apr 29, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Apr 18, 2024
Updated Aug 1, 2024

GitHub

No data