CVE-2019-13379

HIGH

AVTECH Room Alert 3E Firmware < 2.2.5 - Unauthenticated Privilege Escalation via Default Credential Reset

Title source: llm
STIX 2.1

Description

On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=X1PY7kMFkVg

Scores

CVSS v3 8.8
EPSS 0.0300
EPSS Percentile 85.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-668
Status published
Products (1)
avtech/room_alert_3e_firmware < 2.2.5
Published Jul 07, 2019
Tracked Since Feb 18, 2026