Description
Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allowing unauthenticated password changes
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises in versions 3.13 through 4.4 of Integrics EnSwitch when the password update API endpoint can be accessed without proper authentication. By omitting the reset parameter, attackers can modify account passwords for accounts that have no pending reset – these accounts have an empty reset_key that matches the default empty value. Consequently an attacker who has determined a valid username can become an administrator and take control over the system. The weakness is a classic authentication bypass described by CWE‑640, permitting arbitrary password changes, compromise of confidentiality and integrity, and potential full system takeover.

Affected Systems

The affected product is Integrics EnSwitch firmware versions 3.13 to 4.4, inclusive. All deployments of those firmware versions, regardless of network exposure, are vulnerable until a patch or newer release removes the authentication requirement on the /api/json/user/password/update/ endpoint. Users running versions beyond 4.4 are not vulnerable by the published data.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, and the lack of available EPSS data does not reduce the analysis; the vulnerability is actively exploitable with a simple HTTP request. Because the flaw allows unauthenticated manipulation of passwords, an attacker can take over administrator accounts after a brief enumeration of valid usernames. As the attack path requires no privileged credentials or complex setup, the likelihood of exploitation is high. The vulnerability is not listed in the CISA KEV catalog, but the impact remains substantial. The attack vector the data implies is network‑based, targeting the exposed API endpoint.

Generated by OpenCVE AI on October 8, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a supported firmware version newer than 4.4, or apply the vendor patch that requires authentication for the password update API.
  • If upgrade is not feasible, restrict network access to the /api/json/user/password/update/ endpoint so only trusted internal hosts can reach it.
  • Reassign or purge the default empty reset_key for all accounts, ensuring that only accounts with an explicit reset token can change passwords.

Generated by OpenCVE AI on October 8, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Integrics
Integrics enswitch
Vendors & Products Integrics
Integrics enswitch

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.
Title Integrics Enswitch 3.13 through 4.4 Authentication Bypass via Password Reset API
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Integrics Enswitch
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T16:04:49.173Z

Reserved: 2026-10-08T14:06:01.084Z

Link: CVE-2026-107640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:47.343

Modified: 2026-10-08T21:35:53.890

Link: CVE-2026-107640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T08:04:46Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password