Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify the admin account's authentication.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Db Elettronica
Db Elettronica screen Sft Dab 600c |
|
| Vendors & Products |
Db Elettronica
Db Elettronica screen Sft Dab 600c |
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify the admin account's authentication. | |
| Title | Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password Change | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-22T21:35:30.837Z
Updated: 2025-12-22T22:05:16.450Z
Reserved: 2025-12-19T14:03:57.725Z
Link: CVE-2023-53967
Updated: 2025-12-22T21:59:40.338Z
Status : Awaiting Analysis
Published: 2025-12-22T22:16:01.370
Modified: 2025-12-23T14:51:52.650
Link: CVE-2023-53967
No data.
ReportizFlow