FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-10T17:00:00

Updated: 2024-08-05T10:24:33.002Z

Reserved: 2018-09-06T00:00:00

Link: CVE-2018-16591

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-09-10T17:29:00.587

Modified: 2020-08-24T17:37:01.140

Link: CVE-2018-16591

cve-icon Redhat

No data.