Junglewise Threat Intelligence

CVE-2026-94493: Gigatech PDV5701 authentication bypass in WebSocket service

CVE-2026-94493 · Severity: critical · CVSS 10 · Published 2026-09-22

Executive brief

The Gigatech PDV5701 is a door station with a web-based management interface. An unauthenticated attacker can connect directly to the device's WebSocket service and retrieve sensitive administrator credentials and configuration data without logging in, then use those credentials to gain full administrative control of the device, including the ability to modify settings, upload firmware, and reset the system.

Technical details

The PDV5701's WebSocket management interface at /getparameter endpoint lacks authentication checks and returns plaintext administrator credentials and sensitive configuration data to any unauthenticated remote client. An attacker can connect via WebSocket without credentials or Origin header validation and extract the ACCUSER and ACCPASSWD fields, then authenticate as admin via the setlogin action. No patched version is mentioned.

Affected products

  • Gigatech PDV5701 1.0.31_240305_112640

Timeline

  • 2026-07-19: disclosed
  • 2026-09-22: advisory

References