Vulnerabilities > CVE-2021-28936 - Incorrect Authorization vulnerability in Acexy Wireless-N Wifi Repeater Firmware 28.08.06.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
acexy
CWE-863

Summary

The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required.

Vulnerable Configurations

Part Description Count
OS
Acexy
1
Hardware
Acexy
1

Common Weakness Enumeration (CWE)