CVE-2019-11367

CRITICAL

AUO Solar Data Recorder <1.3.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

Scores

CVSS v3 9.8
EPSS 0.0367
EPSS Percentile 87.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522 CWE-311
Status published
Products (1)
auo/solar_data_recorder < 1.3.0
Published Jun 03, 2019
Tracked Since Feb 18, 2026