CVE-2023-53970
HIGHScreen SFT DAB 600/C Firmware 1.9.3 - Auth Bypass
Title source: llmDescription
Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with manipulated session parameters.
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/51459
References (5)
Scores
CVSS v3
7.5
EPSS
0.0042
EPSS Percentile
61.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-306
Status
published
Products (1)
dbbroadcast/sft_dab_600\/c_firmware
1.9.3
Published
Dec 22, 2025
Tracked Since
Feb 18, 2026