Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-53967. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit bypasses authentication by directly changing the admin password via an API call without requiring the old password. It sends a crafted JSON payload to the target endpoint to modify the admin credentials.
Description
Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify the admin account's authentication.
Exploits (1)
This exploit bypasses authentication by directly changing the admin password via an API call without requiring the old password. It sends a crafted JSON payload to the target endpoint to modify the admin credentials.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N