CVE-2019-6441: Critical severity coship rt3050 firmware vulnerability
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-6441.
What is the severity of CVE-2019-6441?
The severity of CVE-2019-6441 is critical with a score of 9.8.
Which devices are affected by CVE-2019-6441?
Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 are affected by this vulnerability.
What is the impact of CVE-2019-6441?
This vulnerability allows an attacker to reset the router's password without any authentication, potentially granting access to the admin interface and control over the router.
Is there a fix available for CVE-2019-6441?
At the moment, there is no fix available for CVE-2019-6441. It is recommended to update to the latest firmware version provided by the vendor when it becomes available.