Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rccf-3gfp-fhpv

Опубликовано: 08 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.

The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.

EPSS

Процентиль: 15%
0.00048
Низкий

8.8 High

CVSS3

Дефекты

CWE-258

Связанные уязвимости

CVSS3: 8.8
nvd
почти 2 года назад

The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.

EPSS

Процентиль: 15%
0.00048
Низкий

8.8 High

CVSS3

Дефекты

CWE-258