Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Authentication Bypass
Vulnerability Description
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST request to the /operator/operator endpoint.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
Vulnerability Type
认证机制不恰当
Vulnerability Title
MENNEKES AMTRON 安全漏洞
Vulnerability Description
MENNEKES AMTRON是MENNEKES公司的一系列电动汽车交流充电桩与壁挂式充电系统。 MENNEKES AMTRON 5.22.3及之前版本存在安全漏洞,该漏洞源于身份验证绕过,可能导致未经身份验证的远程攻击者通过精心构造的POST请求更改用户账户密码。
CVSS Information
N/A
Vulnerability Type
N/A