An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.
History

Wed, 25 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:connectize:ac21000_g6_firmware:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-04T00:00:00.000Z

Updated: 2024-08-02T10:49:08.979Z

Reserved: 2023-01-21T00:00:00.000Z

Link: CVE-2023-24052

cve-icon Vulnrichment

Updated: 2024-08-02T10:49:08.979Z

cve-icon NVD

Status : Modified

Published: 2023-12-04T23:15:23.410

Modified: 2024-11-21T07:47:20.317

Link: CVE-2023-24052

cve-icon Redhat

No data.