CVE-2018-12073
Description
An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a new one within the web interface. Therefore, it is possible to exploit this issue (e.g., in combination with a successful XSS, or at an unattended workstation) to change the admin password to an attacker-chosen value without knowing the current password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Eminent EM4544 devices (firmware 9.10) allow password change without the current password, enabling trivial takeover via XSS or physical access.
Vulnerability
The Eminent EM4544 (firmware version 9.10) web interface does not require the user's current password to set a new one. This missing authentication check means that any request to change the admin password will succeed without verifying the old credential. The affected component is the password change functionality in the web administration panel [1].
Exploitation
An attacker can exploit this by either (a) combining it with a cross-site scripting (XSS) attack to force an authenticated admin's browser to submit a password change request, or (b) gaining physical or remote access to an unattended workstation that has an active admin session. In both cases, no knowledge of the current password is needed; the attacker simply submits the new desired password via the web interface [1].
Impact
Successful exploitation allows an attacker to change the admin password arbitrarily, gaining full administrative control over the device. This can lead to complete compromise of the device's configuration, network access, and any data it handles [1].
Mitigation
No firmware update or official fix has been published by Eminent for this vulnerability. As of the available references, users are advised to restrict network access to the device's web interface (e.g., via firewall rules) and ensure physical security of the device to prevent unauthorized access [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gist.github.com/freetom/2a446a226d0e98807c8b0c1111ef2defmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.