JUNG eNet SMART HOME server 2.2.1/2.3.1 Account Takeover via resetUserPassword
A flaw in JUNG eNet SMART HOME server allows any regular user to reset passwords of admin accounts without authorization, letting them take over the system. This happens because the password reset function doesn't properly check if the user has permission to change other accounts.
The resetUserPassword JSON-RPC method at /jsonrpc/management lacks authorization checks, permitting authenticated low-privileged users (UG_USER) to reset passwords for arbitrary accounts including UG_ADMIN and UG_SUPER_ADMIN groups without current password verification. An attacker sends a crafted JSON-RPC request to overwrite admin credentials, achieving account takeover and privilege escalation to full administrative access.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →