CVE-2024-38468
Published Jun 16, 2024Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
Vendor archive
4 CVEs tagged to vendor guoxinled — 2 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.