On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
http://www.nccst.nat.gov.tw | third party advisory broken link |
https://github.com/cvereveal/CVEs/tree/master/CVE-2019-6451 | third party advisory exploit |
http://www.soyal.com/epaper/e-paper-en-117.html | broken link |
https://www.soyal.com/exhibition/cve-2019-6451/ | broken link |
https://www.soyal.com.tw/cve-2019-6451/ | vendor advisory |