CVE-2023-53740

CRITICAL

Screen SFT DAB Series 1.9.3 - Unauthenticated Authentication Bypass via userManager.cgx Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53740. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit bypasses authentication by directly changing the admin password via an API call without requiring the old password. It sends a crafted JSON payload to the target endpoint to modify the admin credentials.

Description

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/51458

This exploit bypasses authentication by directly changing the admin password via an API call without requiring the old password. It sends a crafted JSON payload to the target endpoint to modify the admin credentials.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Screen SFT DAB 600/C with Firmware 1.9.3
No auth needed
Prerequisites: Network access to the target device · Knowledge of the target IP address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Product product
https://www.screen.it
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51458
Product vendor-advisory vdb-entry
https://www.dbbroadcast.com
Third Party Advisory, Exploit vendor-advisory vdb-entry
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5774.php

Scores

CVSS v3 9.8
EPSS 0.0080
EPSS Percentile 51.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (6)
DB Elettronica Telecomunicazioni SpA/Screen SFT DAB Series - Compact Radio DAB Transmitter 1.9.3
dbbroadcast/sft_dab_015\/c_firmware 1.9.3
dbbroadcast/sft_dab_050\/c_firmware 1.9.3
dbbroadcast/sft_dab_150\/c_firmware 1.9.3
dbbroadcast/sft_dab_300\/c_firmware 1.9.3
dbbroadcast/sft_dab_600\/c_firmware 1.9.3
Published Dec 10, 2025
Tracked Since Feb 18, 2026