Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jfv-vfxw-8q23

Опубликовано: 27 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.

Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.

EPSS

Процентиль: 51%
0.00281
Низкий

8.8 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.

EPSS

Процентиль: 51%
0.00281
Низкий

8.8 High

CVSS3

Дефекты

CWE-798