CVE-2019-7564
9.8
CRITICAL · CVSS 3.0 · EPSS 3.1% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.05% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-05-07 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| coship | rt3050 |
| coship | rt3050 firmware |
| coship | rt3052 |
| coship | rt3052 firmware |
| coship | rt7620 |
| coship | rt7620 firmware |
| coship | wm3300 |
| coship | wm3300 firmware |
References
→ the Explorer · watch your stack · NVD