CVE-2025-28371

CVE Details

Basic Information

Title CVE-2025-28371
Type cve
Published 2025-05-19T14:15:23
Last Seen 2025-05-19T14:18:23

CVSS Information

Base Score 0.0 ()
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description The EnGenius ENH500 access point is vulnerable to incorrect access control, allowing unauthorized password changes without validating the current password.
AI Severity High
Vendor EnGenius Technologies
Product EnGenius ENH500 AP 2T2R
Affected Version V3.0 FW3.7.22

Additional Information

CVE List CVE-2025-28371
CWE List
Bulletin Family cve

Description

EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.

CVSS Score Summary

Base Score: %!f(string=#) ()

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.