Suggested description
The Furuno Felcom250 and Felcom500 devices allowed unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel.
Vulnerability Type
Incorrect Access Control
Vendor of Product
Furuno
Affected Product Code Base
Felcom500 - N/A
Felcom250 - N/A
Reference
https://gist.github.com/CyberSKR/2c30d964d48b5e1518ded88bd953b710
https://cyberskr.com/blog/furuno-felcom.html