Vulnerability Details CVE-2019-12254
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2019-12254
-
cpe:2.3:h:gok:smartbox_4_lan:-
-
cpe:2.3:h:gok:smartbox_4_lan_pro:-
-
cpe:2.3:h:tecson:e-litro_net:-
-
cpe:2.3:h:tecson:lx-net:-
-
cpe:2.3:h:tecson:lx-q-net:-
-
cpe:2.3:o:gok:smartbox_4_lan_firmware:-
-
cpe:2.3:o:gok:smartbox_4_lan_pro_firmware:-
-
cpe:2.3:o:tecson:e-litro_net_firmware:-
-
cpe:2.3:o:tecson:lx-net_firmware:-
-
cpe:2.3:o:tecson:lx-q-net_firmware:-