CVE-2019-15068
CRITICALGigastone Smart Battery A4 Firmware <= r1.7.9 - Unauthenticated Administrator Password Reset
Title source: llmDescription
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://tvn.twcert.org.tw/taiwanvn/TVN-201908003
Third Party Advisory x_refsource_confirm
https://www.twcert.org.tw/subpages/ServeThePublic/public_document_details.aspx?lang=en-US&id=45
Scores
CVSS v3
9.8
EPSS
0.0185
EPSS Percentile
76.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
CWE-306
Status
published
Products (1)
gigastone/smart_battery_a4_firmware
< r1.7.9
Published
Sep 25, 2019
Tracked Since
Feb 18, 2026