spx_restservice FirstReset_handler_func Broken Access Control
Description
A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) condition. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated attacker can remotely trigger a DoS on Lanner IAC-AST2500A BMC via broken access control in the FirstReset_handler_func function.
Vulnerability
A broken access control vulnerability exists in the FirstReset_handler_func function of the spx_restservice component in Lanner Inc IAC-AST2500A standard firmware version 1.10.0. The flaw allows an attacker to send reboot commands to the BMC without proper authentication or authorization checks [1], [2].
Exploitation
An unauthenticated remote attacker can exploit this vulnerability by sending crafted network requests to the BMC's REST service. No prior authentication or user interaction is required. The attacker targets the FirstReset_handler_func endpoint to issue reboot commands [1], [2].
Impact
Successful exploitation causes the BMC to reboot immediately, resulting in a Denial-of-Service (DoS) condition. The BMC becomes inaccessible to legitimate users until the reboot completes. This impacts the availability of the management interface and any dependent remote monitoring or management functions [1], [2].
Mitigation
Fixed firmware versions that address this vulnerability are available from Lanner technical support. Asset owners should contact Lanner to obtain the patched firmware and apply it to affected devices [1], [2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2=1.10.0+ 1 more
- (no CPE)range: =1.10.0
- (no CPE)range: 1.10.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.