CVE-2023-0750
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users - Change the streaming source, compromising the integrity of the stream - Change the streaming destination, compromising the confidentiality of the stream This issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.07%
- CWE
- CWE-602
- Published
- 2023-04-06
- Last modified
- 2026-03-13
Affected products
- Lynx Technik AG Yellowbrik
Weakness type
Related vulnerabilities
- CVE-2026-23478 — Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
- CVE-2025-33025 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-33024 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-32469 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2020-24683 — Authentication Bypass in Symphony Plus
- CVE-2022-20658 — Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerability
- CVE-2022-1525 — Cognex 3D-A1000 Dimensioning System Client-Side Enforcement of Server-Side Security
- CVE-2026-25737 — Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)