Description
Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.
Problem types
CWE-287 Improper Authentication
Product status
Any version before 3.1.0_Build_250820_Rel.57668n
Any version before 3.1.0_Build_250820_Rel.57668n
Any version before 3.1.0_Build_250820_Rel.58873n
Any version before 3.1.0_Build_250820_Rel.58873n
Any version before 3.0.2_Build_250630_Rel.71279n
Any version before 3.0.2_Build_250630_Rel.71279n
Any version before 1.1.1_Build_250625_Rel.64224n
Any version before 1.2.0_Build_250820_Rel.60930n
Any version before 1.2.0_Build_250827_Rel.66817n
Any version before 3.1.0_Build_250625_Rel.65381n
Any version before 3.1.0_Build_250625_Rel.66601n
Any version before 2.1.0_Build_250702_Rel.54300n
Any version before 2.1.0_Build_250702_Rel.54301n
Any version before 2.1.0_Build_250702_Rel.54294n
Any version before 2.1.0_Build_251014_Rel.58331n
Any version before 2.1.0_Build_250701_Rel.44071n
Any version before 2.1.0_Build_250701_Rel.45506n
Any version before 2.1.0_Build_250701_Rel.44555n
Any version before 2.1.0_Build_250701_Rel.46003n
Any version before 2.1.0_Build_250701_Rel.45041n
Any version before 2.1.0_Build_250701_Rel.46796n
Any version before 2.1.0_Build_250701_Rel.46796n
Any version before 2.1.0_Build_250701_Rel.47570n
Any version before 2.1.0_Build_250701_Rel.48425n
Any version before 2.1.0_Build_250701_Rel.49304n
Any version before 2.1.0_Build_250701_Rel.49778n
Any version before 2.1.0_Build_250701_Rel.50397n
Any version before 2.2.0_Build_250826_Rel.56808n
Any version before 2.1.1_Build_250717_Rel.66528n
Any version before 2.1.1_Build_250717_Rel.66632n
Any version before 2.1.1_Build_250717_Rel.67730n
Any version before 2.1.0_Build_250725_Rel.36867n
Any version before 1.1.0_Build_250630_Rel.39597n
Any version before 2.1.0_Build_250701_Rel.39597n
References
www.vigi.com/us/support/download/
www.vigi.com/en/support/download/
www.vigi.com/in/support/download/
www.tp-link.com/us/support/faq/4899/