A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://tvn.twcert.org.tw/taiwanvn/TVN-201908003 | third party advisory |
https://www.twcert.org.tw/subpages/ServeThePublic/public_document_details.aspx?lang=en-US&id=45 | third party advisory |