CVE-2025-28371

EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:engeniustech:enh500_firmware:3.7.22:*:*:*:*:*:*:*
cpe:2.3:h:engeniustech:enh500:3.0:*:*:*:*:*:*:*

History

12 Jun 2025, 16:26

Type Values Removed Values Added
References () https://drive.google.com/file/d/1kQFOyFQYycKynIBjbU8bMx2gYTG3Bxi2/view?usp=sharing - () https://drive.google.com/file/d/1kQFOyFQYycKynIBjbU8bMx2gYTG3Bxi2/view?usp=sharing - Exploit
References () https://pastebin.com/raw/EnL1XT2n - () https://pastebin.com/raw/EnL1XT2n - Third Party Advisory
References () https://pastebin.com/raw/hziq1nGH - () https://pastebin.com/raw/hziq1nGH - Third Party Advisory
CPE cpe:2.3:o:engeniustech:enh500_firmware:3.7.22:*:*:*:*:*:*:*
cpe:2.3:h:engeniustech:enh500:3.0:*:*:*:*:*:*:*
First Time Engeniustech enh500 Firmware
Engeniustech
Engeniustech enh500

21 May 2025, 20:25

Type Values Removed Values Added
Summary
  • (es) El dispositivo EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 es vulnerable a un control de acceso incorrecto mediante la función de cambio de contraseña. El dispositivo no valida la contraseña actual, lo que permite a un atacante enviar una solicitud de cambio de contraseña con una contraseña actual no válida y establecer una nueva.

19 May 2025, 16:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

19 May 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-19 14:15

Updated : 2025-06-12 16:26


NVD link : CVE-2025-28371

Mitre link : CVE-2025-28371

CVE.ORG link : CVE-2025-28371


JSON object : View

Products Affected

engeniustech

  • enh500
  • enh500_firmware
CWE
CWE-284

Improper Access Control