CVE-2019-11523

CRITICAL

Anviz Global M3 Outdoor RFID Access Control - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-11523. PoCs published by wizlab-it.

AI-analyzed exploit summary The repository contains functional exploit code demonstrating CVE-2019-11523, an authentication bypass and information leakage vulnerability in Anviz M3 RFID Access Control devices. The PoC scripts (Python and PHP) send crafted TCP packets to interact with the device's unauthenticated protocol, allowing actions like opening doors, retrieving user data, and altering records.

Description

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

Exploits (1)

nomisec WORKING POC 2 stars
by wizlab-it · poc
https://github.com/wizlab-it/anviz-m3-rfid-cve-2019-11523-poc

The repository contains functional exploit code demonstrating CVE-2019-11523, an authentication bypass and information leakage vulnerability in Anviz M3 RFID Access Control devices. The PoC scripts (Python and PHP) send crafted TCP packets to interact with the device's unauthenticated protocol, allowing actions like opening doors, retrieving user data, and altering records.

Classification
Working Poc 95%
Attack Type
Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Anviz M3 Outdoor RFID Access Control (standalone mode)
No auth needed
Prerequisites: Network access to the Anviz M3 device on TCP port 5010
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Mitigation, Third Party Advisory x_refsource_misc
https://github.com/wizlab-it/anviz-m3-rfid-cve-2019-11523-poc

Scores

CVSS v3 9.8
EPSS 0.0121
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306 CWE-311
Status published
Products (1)
anviz/m3_firmware
Published Jun 06, 2019
Tracked Since Feb 18, 2026