Description
COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attackers can trigger a denial-of-service scenario by sending a malformed request to the setconf endpoint.
Problem types
CWE-306: Missing Authentication for Critical Function
Product status
*
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/50209 (ExploitDB-50209)
www.commax.com (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5666.php (Zero Science Lab Disclosure (ZSL-2021-5666))
www.vulncheck.com/...ctv-bridge-dvr-service-config-write-dos (VulnCheck Advisory: COMMAX Smart Home Ruvie CCTV Bridge DVR Service Config Write / DoS)