CVE-2022-47697

CRITICAL

Comfast Cf-wr623n Firmware < 2.3.0.1 - Password Reset Weakness

Title source: rule

Description

COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts.

Scores

CVSS v3 9.8
EPSS 0.0034
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-640
Status published

Affected Products (1)

comfast_project/cf-wr623n_firmware < 2.3.0.1

Timeline

Published Jan 31, 2023
Tracked Since Feb 18, 2026