A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.CreditsLeon Chen, Y.D. Chen, Laura Tzou, Mars ChengReferenceshttps://tvn.twcert.org.tw/taiwanvn/TVN-201908003https://www.twcert.org.tw/subpages/ServeThePublic/public_document_details.aspx?lang=en-US&id=45