EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to...
Moderate severity
Unreviewed
Published
May 19, 2025
to the GitHub Advisory Database
•
Updated May 19, 2025
Description
Published by the National Vulnerability Database
May 19, 2025
Published to the GitHub Advisory Database
May 19, 2025
Last updated
May 19, 2025
EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.
References