An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
History

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Zlan Information Technology Co.
Zlan Information Technology Co. zlan5143d
Vendors & Products Zlan Information Technology Co.
Zlan Information Technology Co. zlan5143d

Wed, 11 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 16:45:00 +0000

Type Values Removed Values Added
Description An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Title ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-02-11T16:45:23.479Z

Reserved: 2026-01-29T21:07:29.858Z

Link: CVE-2026-24789

cve-icon Vulnrichment

Updated: 2026-02-11T16:45:13.239Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-11T17:16:13.040

Modified: 2026-02-11T18:06:04.010

Link: CVE-2026-24789

cve-icon Redhat

No data.