AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-12254

CRITICAL · CVSS 9.8 EPSS 1.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-05-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-12254
Severity
CRITICAL
CVSS
9.8
EPSS
1.24%

Original NVD Description

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.