Vulnerability record · CVE-2019-6441 · published 21 March 2019
CVE-2019-6441: Coship router apply.cgi unauthenticated admin password reset
Coship · Rt3050 Firmware
The password reset functionality in Shenzhen Coship RT3050, RT3052, RT7620 and WM3300 routers lacks backend validation of the current password and requires no authentication. A remote attacker can POST to apply.cgi to change the admin username and password, taking over the device.
Description
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code, and a very high EPSS score make this an urgent risk for exposed devices.
What it is
The password reset functionality in Shenzhen Coship RT3050, RT3052, RT7620 and WM3300 routers lacks backend validation of the current password and requires no authentication. A remote attacker can POST to apply.cgi to change the admin username and password, taking over the device.
Impact
An attacker gains full administrative control of the router, allowing them to alter configuration, redirect or intercept traffic, and lock out legitimate administrators.
Attack surface
Reachable over the network via HTTP POST to apply.cgi; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Public exploit code exists (Exploit-DB 46180 and Packet Storm references), and EPSS is 0.53612 (98.9th percentile); the CVE is not listed in CISA KEV.
What to do
- Apply vendor firmware updates for the affected Coship models if available; if no fix exists, replace or retire the devices.
- Do not expose the router management interface to the internet; restrict access to a trusted management network.
- Disable remote administration and WAN-side web management where the device supports it.
- Monitor for unauthorized changes to admin credentials and reset them if tampering is suspected.
- Isolate affected routers on a segmented network to limit the impact of compromise.
Detection
- Alert on POST requests to apply.cgi from untrusted or external source addresses.
- Monitor router logs for admin username or password changes outside approved maintenance windows.
- Detect unexpected configuration changes or admin logins from new source IPs.
- Use network monitoring to identify scanning or exploitation attempts against router management ports.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-6441 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-6441), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.