CVE-2019-13406
29.08.2019, 01:15
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.Enginsight
Vendor | Product | Version |
---|---|---|
androvideo | vd_1_firmware | 𝑥 ≤ 230 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References