Overview

Affected version

FH1202 V1.2.0.14(408)

Vulnerability details

An improper access control vulnerability exists in the web management interface of In FH1202 V1.2.0.14(408). By sending a specially crafted unauthenticated HTTP POST request to the goform endpoint with SysToolChangePwd , an attacker can set the password settings of the device.

POC