CirCarLife before 4.3 is susceptible to improper authentication. A system software information disclosure exists due to lack of authentication for /html/device-id. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2018-16671
info:
name: CirCarLife <4.3 - Improper Authentication
author: geeknik
seve
...