Impact
The vulnerability arises in versions 3.13 through 4.4 of Integrics EnSwitch when the password update API endpoint can be accessed without proper authentication. By omitting the reset parameter, attackers can modify account passwords for accounts that have no pending reset – these accounts have an empty reset_key that matches the default empty value. Consequently an attacker who has determined a valid username can become an administrator and take control over the system. The weakness is a classic authentication bypass described by CWE‑640, permitting arbitrary password changes, compromise of confidentiality and integrity, and potential full system takeover.
Affected Systems
The affected product is Integrics EnSwitch firmware versions 3.13 to 4.4, inclusive. All deployments of those firmware versions, regardless of network exposure, are vulnerable until a patch or newer release removes the authentication requirement on the /api/json/user/password/update/ endpoint. Users running versions beyond 4.4 are not vulnerable by the published data.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, and the lack of available EPSS data does not reduce the analysis; the vulnerability is actively exploitable with a simple HTTP request. Because the flaw allows unauthenticated manipulation of passwords, an attacker can take over administrator accounts after a brief enumeration of valid usernames. As the attack path requires no privileged credentials or complex setup, the likelihood of exploitation is high. The vulnerability is not listed in the CISA KEV catalog, but the impact remains substantial. The attack vector the data implies is network‑based, targeting the exposed API endpoint.
OpenCVE Enrichment