Executive brief
The Gigatech PDV5701 is a door station with a web-based management interface. An unauthenticated attacker can connect directly to the device's WebSocket service and retrieve sensitive administrator credentials and configuration data without logging in, then use those credentials to gain full administrative control of the device, including the ability to modify settings, upload firmware, and reset the system.
Technical details
The PDV5701's WebSocket management interface at /getparameter endpoint lacks authentication checks and returns plaintext administrator credentials and sensitive configuration data to any unauthenticated remote client. An attacker can connect via WebSocket without credentials or Origin header validation and extract the ACCUSER and ACCPASSWD fields, then authenticate as admin via the setlogin action. No patched version is mentioned.
Affected products
- Gigatech PDV5701 1.0.31_240305_112640
Timeline
- 2026-07-19: disclosed
- 2026-09-22: advisory