CVE-2023-53740
EUVD-2023-6018610.12.2025, 21:16
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dbbroadcast | sft_dab_015\/c_firmware | 1.9.3 |
| dbbroadcast | sft_dab_050\/c_firmware | 1.9.3 |
| dbbroadcast | sft_dab_150\/c_firmware | 1.9.3 |
| dbbroadcast | sft_dab_300\/c_firmware | 1.9.3 |
| dbbroadcast | sft_dab_600\/c_firmware | 1.9.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References