Vulnerabilities > CVE-2019-6961 - Missing Authorization vulnerability in Rdkcentral Rdkb Ccsppandm Rdkb201812171
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
Incorrect access control in actionHandlerUtility.php in the RDK RDKB-20181217-1 WebUI module allows a logged in user to control DDNS, QoS, RIP, and other privileged configurations (intended only for the network operator) by sending an HTTP POST to the PHP backend, because the page filtering for non-superuser (in header.php) is done only for GET requests and not for direct AJAX calls.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |