CVE-2019-12254: Gok Smartbox 4 Lan Firmware

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.

Affected products

  • Gok Smartbox 4 Lan Firmware: any version
  • Gok Smartbox 4 Lan Pro Firmware: any version
  • Tecson E-Litro Net Firmware: any version
  • Tecson Lx-Net Firmware: any version
  • Tecson Lx-Q-Net Firmware: any version

Published 2022-05-06. Last modified 2026-06-17.