First published: Thu Aug 29 2019(Updated: )
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Androvideo Vd 1 | <=230 | |
Androvideo Vd 1 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13406 is classified as a critical vulnerability due to its potential for unauthorized APK installations.
To fix CVE-2019-13406, upgrade the Advan VD-1 firmware to version 231 or later, which addresses this vulnerability.
CVE-2019-13406 is a broken access control vulnerability that allows attackers to install arbitrary APKs.
Firmware versions up to 230 of the Advan VD-1 are affected by CVE-2019-13406.
An attacker exploiting CVE-2019-13406 can install malicious applications on the device without authentication.