PT-2021-10710 · Inim Electronics · Smartlan/G/Si

Gjoko Krstic

·

Published

2021-04-29

·

Updated

2021-06-15

·

CVE-2020-21995

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Inim Electronics Smartliving SmartLAN/G/SI versions prior to 7.x
Description: The issue allows an attacker to gain access to the system using default hardcoded credentials, potentially leading to unauthorized access via Telnet, SSH, and FTP.
Recommendations: For versions prior to 7.x, change the default credentials to unique and strong passwords to prevent unauthorized access. As a temporary workaround, consider restricting access to Telnet, SSH, and FTP services until the credentials are changed.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-21995

Affected Products

Smartlan/G/Si