CVE-2021-47706

HIGH

COMMAX Biometric Access Control System 1.0.0 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47706. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in COMMAX Biometric Access Control System 1.0.0 by forging specific cookies to access sensitive information without authentication.

Description

COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and disclose sensitive information.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/50206

This exploit demonstrates an authentication bypass vulnerability in COMMAX Biometric Access Control System 1.0.0 by forging specific cookies to access sensitive information without authentication.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: COMMAX Biometric Access Control System 1.0.0
No auth needed
Prerequisites: Network access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/50206
Various Sources product
https://www.commax.com
Various Sources product
https://www.commax.com/product/
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5661.php

Scores

CVSS v4 8.7
EPSS 0.0043
EPSS Percentile 34.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-565
Status published
Products (1)
COMMAX Co., Ltd./COMMAX Biometric Access Control System 1.0.0
Published Dec 09, 2025
Tracked Since Feb 18, 2026