CVE-2019-6441 describes a critical unauthenticated password reset vulnerability affecting several Shenzhen Coship RT3050, RT3052, RT7620, and WM3300 router models. This flaw allows an unauthenticated attacker to change the administrative username and password by sending a POST request to the apply.cgi file, bypassing any authentication or current password validation. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB proof-of-concept exists, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0.40CPE matchmatch criteria | cpe:2.3:o:coship:rt3050_firmware:4.0.0.40:*:*:*:*:*:*:* | ||
4.0.0.48CPE matchmatch criteria | cpe:2.3:o:coship:rt3052_firmware:4.0.0.48:*:*:*:*:*:*:* | ||
10.0.0.49CPE matchmatch criteria | cpe:2.3:o:coship:rt7620_firmware:10.0.0.49:*:*:*:*:*:*:* | ||
5.0.0.54CPE matchmatch criteria | cpe:2.3:o:coship:wm3300_firmware:5.0.0.54:*:*:*:*:*:*:* | ||
5.0.0.55CPE matchmatch criteria | cpe:2.3:o:coship:wm3300_firmware:5.0.0.55:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.