Description
COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and disclose sensitive information.
Problem types
CWE-565: Reliance on Cookies without Validation and Integrity Checking
Product status
1.0.0
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/50206 (ExploitDB-50206)
www.commax.com (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5661.php (Zero Science Lab Disclosure (ZSL-2021-5661))
www.commax.com/product/ (COMMAX Biometric Access Control System 1.0.0 Product Page)
www.vulncheck.com/...ss-control-system-authentication-bypass (VulnCheck Advisory: COMMAX Biometric Access Control System Authentication Bypass)