CVE-2022-45636 Information

Description

An issue discovered in MEGAFEIS BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.

Reference

https://labs.withsecure.com/advisories/insecure-authorization-scheme-for-api-requests-in-dbd–mobile-co https://github.com/WithSecureLabs/megafeis-palm/tree/main/CVE-2022-45636

Share on: