Логотип exploitDog
bind:CVE-2025-26410
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-26410

Количество 2

Количество 2

nvd логотип

CVE-2025-26410

12 месяцев назад

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-jj4x-g447-hm4m

12 месяцев назад

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-26410

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-jj4x-g447-hm4m

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.

CVSS3: 9.8
0%
Низкий
12 месяцев назад

Уязвимостей на страницу