The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account…
SEC-VLab·CWE-620·Published 2024-12-12