Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 02 Jan 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast sft Dab 600\/c
Dbbroadcast sft Dab 600\/c Firmware
CPEs cpe:2.3:h:dbbroadcast:sft_dab_600\/c:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:sft_dab_600\/c_firmware:1.9.3:*:*:*:*:*:*:*
Vendors & Products Dbbroadcast sft Dab 600\/c
Dbbroadcast sft Dab 600\/c Firmware
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Thu, 11 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast
Dbbroadcast sft Dab Series
Vendors & Products Dbbroadcast
Dbbroadcast sft Dab Series

Wed, 10 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Description Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.
Title Screen SFT DAB 1.9.3 Authentication Bypass via Session Management Weakness
Weaknesses CWE-384
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-11T18:52:11.478Z

Reserved: 2025-12-08T23:43:00.992Z

Link: CVE-2023-53775

cve-icon Vulnrichment

Updated: 2025-12-11T15:51:43.708Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-10T22:16:18.363

Modified: 2026-01-02T13:51:51.740

Link: CVE-2023-53775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-11T16:20:15Z

Weaknesses