GHSA-qxpp-mcfv-63xpCriticalCVSS 9.1

Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json...

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.

🔗 References (5)