CVE-2021-40350
Description
webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspecified Cookie header. Authentication bypass can be achieved by including an administrative cookie that the device does not validate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authentication bypass in Christie Digital DWU850-GS V06.46 via crafted cookie allows unauthenticated attacker to create privileged accounts.
Vulnerability
The vulnerability exists in the webctrl.cgi.elf binary on Christie Digital DWU850-GS devices running firmware version V06.46. An attacker can bypass authentication by including a specific administrative cookie in a crafted HTTP request; the device does not validate the cookie, allowing unauthorized actions. [1]
Exploitation
An attacker sends a POST request to the device with a unique cookie and account credentials (e.g., username bypassadmin, password bypass). The device accepts the request without proper authentication and creates a new privileged account. The response echoes the cookie, and the attacker can then use the created account to log in. [1]
Impact
Successful exploitation grants the attacker full administrative access to the device. This can be leveraged to modify device configurations, set rogue DHCP servers, and potentially disrupt network services. [1]
Mitigation
No official fix or mitigation has been disclosed by Christie Digital as of the publication date. The vulnerability discoverer has kept the exploit vector private to prevent widespread abuse. Users should monitor for firmware updates from Christie Digital. [1]
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Christie Digital/DWU850-GSdescription
- Range: V06.46
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.