CVE-2024-22179
The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-302
- Published
- 2024-04-18
- Last modified
- 2026-03-13
Affected products
- Electrolink Compact DAB Transmitter
- Electrolink Compact DAB Transmitter
- Electrolink Compact DAB Transmitter
- Electrolink Medium DAB Transmitter
- Electrolink Medium DAB Transmitter
- Electrolink Medium DAB Transmitter
- Electrolink High Power DAB Transmitter
- Electrolink High Power DAB Transmitter
Weakness type
Related vulnerabilities
- CVE-2026-77508 — Weblate: Unverified REST API email changes
- CVE-2026-13267 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-5423 — Subscription Authentication Bypass via Unverified connectionParams.jwt
- CVE-2026-50528 — .NET Security Feature Bypass Vulnerability
- CVE-2026-47303 — ASP.NET Core Elevation of Privilege Vulnerability
- CVE-2026-48117 — DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-34460 — NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping