BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
https://sku11army.blogspot.com/2020/03/bwa-multiple-vulnerabilities-in-direx.html | third party advisory exploit |