AC Smart II contains an authentication bypass caused by a hidden password reset form that can be manipulated to change the administrator password without verifying login or permissions, letting attackers change admin passwords without authorization.
id: CVE-2025-10204
info:
name: AC Smart II - Authentication Bypass
author: theeldruin
severit
...