Site icon API Security Blog

JVN#77203800: OET-213H-BTS1 missing authorization check in the initial configuration

OET-213H-BTS1 is a digital temperature measurement and face recognition terminal, developed by Zhejiang Uniview Technologies Co.,Ltd and provided by Atsumi Electric Co., Ltd. The initial configuration of the product is ​insecure (CWE-1188), it does not perform an authorization check when processing the API requests. ## Impact The product may be configured and controlled from within the adjacent network without authentication. ## Solution Update the configuration You can enable HTTP authentication. For more details, refer to the information in the Vendor Status section below. ## Products Affected This vulnerability is reported for the following products sold in Japan by Atsumi Electric co., Ltd. …Read More

Exit mobile version