Описание
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.3 (включая)
Одновременно
cpe:2.3:o:govicture:wr1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:govicture:wr1200:-:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00122
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-798
Связанные уязвимости
github
около 4 лет назад
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).
EPSS
Процентиль: 32%
0.00122
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-798