PT-2018-5428 · Planex · Planex Cs-W50Hd
Kenney Lu
·
Publicado
2018-08-24
·
Atualizado
2018-11-21
·
CVE-2017-12574
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
PLANEX CS-W50HD devices with firmware prior to 030720
Description:
A hardcoded credential
supervisor:dangerous is injected into the web authentication database /.htpasswd during the booting process, allowing attackers to gain unauthorized access and control the device completely. The account cannot be modified or deleted.Recommendations:
For PLANEX CS-W50HD devices with firmware prior to 030720, update the firmware to version 030720 or later to remove the hardcoded credential. As a temporary workaround, consider restricting access to the device until the firmware can be updated.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Planex Cs-W50Hd