Sceawere
Vulnerability Detail
CVE-2026-94493UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Gigatech PDV5701 Missing Authentication Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 2h ago
- Vendor
- Gigatech
- Product
- PDV5701
- Attack Type
- Missing Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-22T01:16:56.437Z",
"pubdate": "2026-09-22T01:16:56.437Z",
"executiveSummary": "A critical security vulnerability has been identified in the Gigatech PDV5701 (version 1.0.31_240305_112640) involving the WebSocket Service.\nThe vulnerability is characterized by a failure to enforce authentication mechanisms for the /index.html endpoint, leading to unauthorized access.\nThis flaw allows remote, unauthenticated attackers to interact with the WebSocket Service, potentially bypassing intended security controls.\nThe risk is elevated by the public availability of exploit code, which may be leveraged by malicious actors to compromise device integrity.\nThe vendor has been notified regarding this disclosure; however, there has been no documented response or remediation provided.\nImpact includes unauthorized access to system functionalities governed by the WebSocket interface, creating a significant security risk for the affected product.",
"technicalDetails": "The vulnerability resides within the WebSocket Service component of the Gigatech PDV5701 device, specifically involving improper handling of incoming requests to the /index.html file path.\nThe root cause is a failure in the authorization logic, where the system fails to validate user credentials or session tokens before permitting interactions with the WebSocket Service.\nAttackers can trigger this vulnerability by initiating a remote WebSocket connection to the targeted device without requiring any prior authentication.\nThe attack flow proceeds as follows: 1) The attacker initiates a connection request targeting the exposed WebSocket Service; 2) The server incorrectly grants access to the /index.html processing logic without session validation; 3) The attacker successfully interacts with the component as if they were an authenticated user.\nBecause the WebSocket Service handles asynchronous communication, the lack of authentication allows an attacker to inject arbitrary commands or monitor data streams intended only for authenticated administrative or user sessions.\nThe vulnerability is remotely exploitable, requiring only network reachability to the device's management interface or service port. No specific user interaction is required from legitimate users to facilitate the exploit.\nThe post-exploitation impact includes unauthorized control over the device functions managed by the WebSocket interface, potential sensitive data exposure, and the ability to leverage the device for further malicious activities within the local network.\nThe public availability of the exploit necessitates immediate defensive measures, as the barrier to entry for potential attackers has been significantly lowered.\nSystem logs may not adequately capture or flag these unauthenticated WebSocket connections, potentially allowing for persistent, covert access if the service remains reachable from untrusted network segments."
}