The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.
2020-07-29T18:15:13.203
2024-11-21T04:37:55.253
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nec | sv9100_firmware | ≥ 7.0 | Yes |
Hardware | nec | sv9100 | - | No |