CVE-2018-9162
CRITICALContec Smart Home 4.15 - Unauthenticated User Management via new_user.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-9162. PoCs published by Z3ro0ne.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated password reset vulnerability in Contec smart home version 4.15. It allows an attacker to reset the admin password, create new users, edit existing users, and delete users without authentication.
Description
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.
Exploits (1)
This exploit demonstrates an unauthenticated password reset vulnerability in Contec smart home version 4.15. It allows an attacker to reset the admin password, create new users, edit existing users, and delete users without authentication.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H