Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.