← Vulnerability feed

Vulnerability record · CVE-2023-53969 · published 22 December 2025

CVE-2023-53969: Dbbroadcast sft dab 600\/c firmware missing authentication for critical function vulnerability

Dbbroadcast · Sft Dab 600\/C Firmware

Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper authentication.

9.3 CVSS 4.0 Critical EPSS 0.51% · top 58.7% CWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper authentication.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-53969 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2023-53967Dbbroadcast sft dab 600\/c firmware missing authentication for critical function vulnerabilityScreen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requir…EPSS 0.51%9.3CVE-2023-53968Dbbroadcast sft dab 600\/c firmware missing authentication for critical function vulnerabilityScreen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting…EPSS 0.64%8.7CVE-2023-53970Dbbroadcast sft dab 600\/c firmware missing authentication for critical function vulnerabilityScreen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusi…EPSS 0.51%8.7CVE-2023-53776Dbbroadcast sft dab 600\/c firmware vulnerabilityScreen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound ses…EPSS 0.48%8.6CVE-2023-53740Dbbroadcast sft dab 015\/c firmware missing authorization vulnerabilityScreen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current…EPSS 0.88%7.1CVE-2023-53775Dbbroadcast sft dab 600\/c firmware vulnerabilityScreen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session manage…EPSS 0.40%6.9CVE-2023-7328Dbbroadcast sft dab 600\/c firmware missing authentication for critical function vulnerabilityScreen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated…EPSS 0.35%5.7CVE-2023-33684Dbbroadcast sft dab 600\/c bios vulnerabilityWeak session management in DB Elettronica Telecomunicazioni SpA SFT DAB 600/C Firmware: 1.9.3 Bios firmware: 7.1 (Apr 19 2021) Gui: 2.46 FPGA: 169.55…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2023-53969), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.