Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify the admin account's authentication.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify the admin account's authentication. | |
| Title | Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password Change | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-22T22:05:16.450Z
Reserved: 2025-12-19T14:03:57.725Z
Link: CVE-2023-53967
Updated: 2025-12-22T21:59:40.338Z
Status : Received
Published: 2025-12-22T22:16:01.370
Modified: 2025-12-22T22:16:01.370
Link: CVE-2023-53967
No data.
OpenCVE Enrichment
No data.