CVE-2018-25134
Unknown
Unknown - Not Provided
Authentication Bypass in Synaccess netBooter Allows Admin Account Creation
Publication date: 2025-12-24
Last updated on: 2025-12-24
Assigner: VulnCheck
Description
Description
Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by sending crafted POST requests to create administrative accounts and gain unauthorized control over power supply management.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| synaccess | netbooter | 4.0 |
| synaccess | netbooter | 5.53 |
| synaccess | netbooter | 6.5 |
| synaccess | netbooter | 6.8 |
| synaccess | netbooter | 6.8C |
| synaccess | netbooter | 6.10 |
| synaccess | netbooter | 6.4A |
| synaccess | netbooter | 6.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |