peter bassill · operator
$ cve CVE-2019-7564 JSON

CVE-2019-7564

9.8
CRITICAL · CVSS 3.0 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.05% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2019-05-07
Last modified2026-06-17

Affected (8)

VendorProduct
coshiprt3050
coshiprt3050 firmware
coshiprt3052
coshiprt3052 firmware
coshiprt7620
coshiprt7620 firmware
coshipwm3300
coshipwm3300 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD