High severity7.5NVD Advisory· Published Aug 29, 2019· Updated Jun 17, 2026
CVE-2019-13406
CVE-2019-13406
Description
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3up to 230+ 1 more
- (no CPE)range: up to 230
- cpe:2.3:o:androvideo:vd_1_firmware:*:*:*:*:*:*:*:*range: <=230
Patches
Vulnerability mechanics
References
3- gist.github.com/keniver/f5155b42eb278ec0273b83565b64235bnvdExploitThird Party Advisory
- surl.twcert.org.tw/hVut7nvdThird Party Advisory
- tvn.twcert.org.tw/taiwanvn/TVN-201906007nvdThird Party Advisory
News mentions
0No linked articles in our index yet.