Description
Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.
Problem types
Product status
S532
X916
X915
X912
R20A-2
C313W-2
NS-2
NC-2
NX-2
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5862.php (Zero Science Lab Disclosure (ZSL-2024-5862))
packetstormsecurity.com/files/182870/ (Packet Storm Security Exploit Entry)
cxsecurity.com/issue/WLB-2024110042 (CXSecurity Vulnerability Listing)
www.vulncheck.com/...oper-access-control-via-serviceshttpapi (VulnCheck Advisory: Akuvox Smart Intercom S539 Improper Access Control via ServicesHTTPAPI)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.