On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?actionResetDefaults&srcRA reset and using the default credentials to get in.
Publication date: Sun, 07 Jul 2019 21:15:00 +0000