Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5qf-h3wv-5gv7

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly generated credentials via a network request. Attackers can send a specific hex-encoded command to port 12777 to obtain username and password, enabling direct SSH access to the device.

Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly generated credentials via a network request. Attackers can send a specific hex-encoded command to port 12777 to obtain username and password, enabling direct SSH access to the device.

EPSS

Процентиль: 49%
0.00264
Низкий

8.7 High

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
около 2 месяцев назад

Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly generated credentials via a network request. Attackers can send a specific hex-encoded command to port 12777 to obtain username and password, enabling direct SSH access to the device.

EPSS

Процентиль: 49%
0.00264
Низкий

8.7 High

CVSS4

Дефекты

CWE-306