GHSA-v63x-fj84-mcjfMediumCVSS 6.3
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS...
🔗 CVE IDs covered (1)
📋 Description
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem.