CVE-2023-53741

HIGH

Screen SFT DAB 1.9.3 - Auth Bypass

Title source: llm

Description

Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP address-bound session identifiers. Attackers can exploit the vulnerable API by intercepting and reusing established sessions to remove user accounts without proper authorization.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/51457

Scores

CVSS v3 8.1
EPSS 0.0039
EPSS Percentile 59.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-384
Status published
Products (6)
dbbroadcast/sft_dab_015\/c_firmware 1.9.3
dbbroadcast/sft_dab_050\/c_firmware 1.9.3
dbbroadcast/sft_dab_150\/c_firmware 1.9.3
dbbroadcast/sft_dab_300\/c_firmware 1.9.3
dbbroadcast/sft_dab_600\/c_firmware 1.9.3
DB Elettronica Telecomunicazioni SpA/Screen SFT DAB Series - Compact Radio DAB Transmitter 1.9.3
Published Dec 10, 2025
Tracked Since Feb 18, 2026