Impact
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication. This missing authentication flaw permits unauthorized credential alteration, potentially leading to full control over the device and any connected systems.
Affected Systems
The ZLAN5143D device manufactured by ZLAN Information Technology Co. is affected. No specific firmware versions are listed; therefore, all installations of this model are considered vulnerable until a patch is released.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 9.3, indicating a high severity. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the CVE is not listed in the CISA KEV catalog. Nevertheless, attackers could remotely invoke the vulnerable API over the network, modify the password, and gain full administrative access to the device.
OpenCVE Enrichment