Vulnerabilities > Avtech > Room Alert 3E Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-07-07 CVE-2019-13379 Exposure of Resource to Wrong Sphere vulnerability in Avtech Room Alert 3E Firmware
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
network
low complexity
avtech CWE-668
critical
9.0