Vulnerabilities > CVE-2022-45636 - Missing Authorization vulnerability in Megafeis Bofei Dbd+ 1.4.3/1.4.4

047910
CVSS 8.1 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
low complexity
megafeis
CWE-862

Summary

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.

Vulnerable Configurations

Part Description Count
Application
Megafeis
2

Common Weakness Enumeration (CWE)