IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/aliasrobotics/RVD/issues/3327 | third party advisory |