An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
http://shenzhen.com | broken link |
http://zbt.com | vendor advisory |
https://blog.prodefense.io/zbt-we1626-wireless-router-cve-disclosures-b3534484d97d | third party advisory |