{"id":60527,"date":"2024-11-27T20:32:03","date_gmt":"2024-11-27T17:32:03","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182870\/ZSL-2024-5862.txt"},"modified":"2024-11-27T20:32:03","modified_gmt":"2024-11-27T17:32:03","slug":"akuvox-smart-intercom-doorphone-serviceshttpapi-improper-access-control","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/akuvox-smart-intercom-doorphone-serviceshttpapi-improper-access-control\/","title":{"rendered":"Akuvox Smart Intercom\/Doorphone ServicesHTTPAPI Improper Access Control"},"content":{"rendered":"<p>Akuvox Smart Intercom\/Doorphone ServicesHTTPAPI Improper Access Control<\/p>\n<p>Vendor: The Akuvox Company<br \/>Product web page: https:\/\/www.akuvox.com<br \/>Affected version: Doorphone:<br \/>S539<br \/>S532<br \/>X916<br \/>X915<br \/>X912<br \/>R29<br \/>Intercom:<br \/>E16C<br \/>R20K-2<br \/>R20A-2<br \/>C313W-2<br \/>NS-2<br \/>NC-2<br \/>NX-2<br \/>Firmware: 912.30.1.137<\/p>\n<p>Summary: Vandal-resistant Door Phone for High-end Buildings. Offering<br \/>top-of-the-line features, Akuvox X912 is targeted at high-end residential<br \/>and commercial projects. With a compact size, it is perfect for buildings<br \/>with limited installation space.<\/p>\n<p>Desc: The Akuvox Smart Intercom\/Doorphone suffers from an insecure service<br \/>API access control. The vulnerability in ServicesHTTPAPI endpoint allows<br \/>users with &#8220;User&#8221; privileges to modify API access settings and configurations.<br \/>This improper access control permits privilege escalation, enabling unauthorized<br \/>access to administrative functionalities. Exploitation of this issue could<br \/>compromise system integrity and lead to unauthorized system modifications.<\/p>\n<p>Tested on: lighttpd\/1.4.30<br \/>EasyHttpServer<\/p>\n<p>Vulnerability discovered by Gjoko &#8216;LiquidWorm&#8217; Krstic<br \/>@zeroscience<\/p>\n<p>Advisory ID: ZSL-2024-5862<br \/>Advisory URL: https:\/\/www.zeroscience.mk\/en\/vulnerabilities\/ZSL-2024-5862.php<\/p>\n<p>25.02.2024<\/p>\n<p>&#8212;<\/p>\n<p>http:\/\/192.168.1.2\/#\/ServicesHTTPAPI<br \/># user:user<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Akuvox Smart Intercom\/Doorphone ServicesHTTPAPI Improper Access Control Vendor: The Akuvox CompanyProduct web page: https:\/\/www.akuvox.comAffected version: Doorphone:S539S532X916X915X912R29Intercom:E16CR20K-2R20A-2C313W-2NS-2NC-2NX-2Firmware: 912.30.1.137 Summary: Vandal-resistant Door Phone for High-end Buildings. Offeringtop-of-the-line features, Akuvox X912 is targeted at high-end residentialand commercial projects. With a compact size, it is perfect for buildingswith limited installation space. Desc: The Akuvox Smart Intercom\/Doorphone suffers from an &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-60527","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=60527"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60527\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=60527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=60527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=60527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}