Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dbbroadcast
Dbbroadcast sft Dab Series |
|
| Vendors & Products |
Dbbroadcast
Dbbroadcast sft Dab Series |
Wed, 10 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account. | |
| Title | Screen SFT DAB 1.9.3 Authentication Bypass via Admin Password Change | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-11T18:52:23.204Z
Reserved: 2025-12-07T13:16:38.432Z
Link: CVE-2023-53740
Updated: 2025-12-11T15:52:17.156Z
Status : Received
Published: 2025-12-10T21:16:03.233
Modified: 2025-12-11T19:15:51.637
Link: CVE-2023-53740
No data.