Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj4x-g447-hm4m

Опубликовано: 11 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.

EPSS

Процентиль: 44%
0.00218
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
12 месяцев назад

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.

EPSS

Процентиль: 44%
0.00218
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798