VYPR

RDKB-20181217-1 WebUI

by RDK

CVEs (1)

  • CVE-2019-6961MedJun 20, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in actionHandlerUtility.php in the RDK RDKB-20181217-1 WebUI module allows a logged in user to control DDNS, QoS, RIP, and other privileged configurations (intended only for the network operator) by sending an HTTP POST to the PHP backend, because the…