Vulnerabilities > CVE-2019-6961 - Missing Authorization vulnerability in Rdkcentral Rdkb Ccsppandm Rdkb201812171

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
rdkcentral
CWE-862

Summary

Incorrect access control in actionHandlerUtility.php in the RDK RDKB-20181217-1 WebUI module allows a logged in user to control DDNS, QoS, RIP, and other privileged configurations (intended only for the network operator) by sending an HTTP POST to the PHP backend, because the page filtering for non-superuser (in header.php) is done only for GET requests and not for direct AJAX calls.

Vulnerable Configurations

Part Description Count
Application
Rdkcentral
1

Common Weakness Enumeration (CWE)