Impact
An authenticated low‑privileged user can craft POST requests to change the passwords of the admin (operator) and manufacturer accounts on Mennekes Amtron devices. This flaw allows an attacker with limited rights to become an administrator, giving full control over the device, including configuration, firmware updates and all related operational functions. The vulnerability is a clear privilege‑management issue, which is reflected by CWE‑269.
Affected Systems
Mennekes Amtron series firmware versions up to and including 5.22.3 are affected. Devices running any of these firmware releases that expose the web interface or API are susceptible to the exploit.
Risk and Exploitability
The CVSS score of 9.3 classifies this as Critical, indicating a high potential for damage. No EPSS value is available, and the flaw is not listed in CISA’s KEV catalog. The exploit requires an authenticated low‑privileged user, so it is not purely publicly exploitable, but once access is obtained it can be escalated to full administrative control.
OpenCVE Enrichment