Critical severity9.8NVD Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2019-6441
CVE-2019-6441
Description
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:o:coship:rt3050_firmware:4.0.0.40:*:*:*:*:*:*:*
- cpe:2.3:o:coship:rt3052_firmware:4.0.0.48:*:*:*:*:*:*:*
- cpe:2.3:o:coship:rt7620_firmware:10.0.0.49:*:*:*:*:*:*:*
cpe:2.3:o:coship:wm3300_firmware:5.0.0.54:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:coship:wm3300_firmware:5.0.0.54:*:*:*:*:*:*:*
- cpe:2.3:o:coship:wm3300_firmware:5.0.0.55:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- packetstormsecurity.com/files/151202/Coship-Wireless-Router-Unauthenticated-Admin-Password-Reset.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/151202/Coship-Wireless-Router-Unauthenticated-Admin-Password-Reset.htmlnvdExploitThird Party AdvisoryVDB Entry
- vulmon.com/exploitdetailsnvdExploitThird Party Advisory
- www.anquanke.com/vul/id/1451446nvdExploitThird Party Advisory
- www.exploit-db.com/exploits/46180nvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/46180/nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.