CVE-2025-28371
19.05.2025, 14:15
EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.Enginsight
Vendor | Product | Version |
---|---|---|
engeniustech | enh500_firmware | 3.7.22 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration