Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.
The vulnerability of the CWE-425 class (Direct Request / Forced Browsing) consists of the lack of proper permission verification for direct HTTP requests to device resources. An attacker can bypass access control mechanisms by sending crafted HTTP requests directly to protected resources or API endpoints. No authentication or user interaction is required, and the attack is possible remotely over the network.
An attacker can gain access to data collected by the production line monitoring device, delete this data, or modify device settings, which may disrupt monitoring and event logging processes in an industrial environment.
The manufacturer (INABA) has not indicated an available patched version in the description. Patches available from the manufacturer should be applied according to the references. It is also recommended to restrict network access to the device through isolation in the OT/ICS network, use firewalls, and avoid direct exposure of the device to the internet.
CHOCO TEI WATCHER mini (IB-MCT001) — all software versions
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H