Vulnerabilities > CVE-2020-12734 - Missing Authorization vulnerability in Depstech Wifi Digital Microscope 3 Firmware

047910
CVSS 8.1 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
low complexity
depstech
CWE-862

Summary

DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owner, because there is no way to reset to Factory Default settings.

Vulnerable Configurations

Part Description Count
OS
Depstech
1
Hardware
Depstech
1

Common Weakness Enumeration (CWE)