← back
CVE-2025-10204highobserved exploitationCWE-306

Unauth Admin Reset Password on AC Smart II

58Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.1epss 0.5%
from disclosure to weapon
Published on NVDSep 14
VulnCheck+108d
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
yesVulnCheck
A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetting the administrator password. The attacker can manipulate the page using developer tools to display and use the form. This form allows you to change the administrator password without verifying login status or user permissions.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N