Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8f24-hh72-5gf6

Опубликовано: 16 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 4.5

Описание

Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerability is caused by an insufficient fix for CVE-2024-39838.

Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerability is caused by an insufficient fix for CVE-2024-39838.

EPSS

Процентиль: 2%
0.00013
Низкий

6.8 Medium

CVSS4

4.5 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 4.5
nvd
7 месяцев назад

Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerability is caused by an insufficient fix for CVE-2024-39838.

EPSS

Процентиль: 2%
0.00013
Низкий

6.8 Medium

CVSS4

4.5 Medium

CVSS3

Дефекты

CWE-798