CRITICAL · 9.8

CVE-2019-12254

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user wi...

Vulnerability Description

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GokSmartbox 4 Lan FirmwareAll versions
GokSmartbox 4 Lan-
GokSmartbox 4 Lan Pro FirmwareAll versions
GokSmartbox 4 Lan Pro-
TecsonLx-Q-Net FirmwareAll versions
TecsonLx-Q-Net-
TecsonLx-Net FirmwareAll versions
TecsonLx-Net-
TecsonE-Litro Net FirmwareAll versions
TecsonE-Litro Net-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-12254?

CVE-2019-12254 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user wi...

How severe is CVE-2019-12254?

CVE-2019-12254 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-12254?

Check the references section above for vendor advisories and patch information. Affected products include: Gok Smartbox 4 Lan Firmware, Gok Smartbox 4 Lan, Gok Smartbox 4 Lan Pro Firmware, Gok Smartbox 4 Lan Pro, Tecson Lx-Q-Net Firmware.