An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentials are submitted.
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
Link | Tags |
---|---|
https://github.com/strik3r0x1/Vulns/blob/main/User%20enumeration%20-%20Elenos.md | third party advisory exploit |