PT-2015-3335 · Gynoii · Gynoii

Published

2015-07-04

·

Updated

2017-04-13

·

CVE-2015-2881

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Gynoii (affected versions not specified)
Description The issue is related to the presence of predefined 'guest' and 'admin' accounts with passwords 'guest' and '12345' respectively. This could allow a remote attacker to gain access to the device using the web interface.
Recommendations For all affected versions, consider changing the default passwords of the 'guest' and 'admin' accounts to strong, unique passwords to prevent unauthorized access. As a temporary workaround, restrict access to the web interface until the issue is resolved. Avoid using the default passwords for the 'guest' and 'admin' accounts in the device configuration.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02469
CVE-2015-2881

Affected Products

Gynoii