PT-2021-10710 · Inim Electronics · Smartlan/G/Si
Gjoko Krstic
·
Published
2021-04-29
·
Updated
2021-06-15
·
CVE-2020-21995
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Inim Electronics Smartliving SmartLAN/G/SI versions prior to 7.x
Description:
The issue allows an attacker to gain access to the system using default hardcoded credentials, potentially leading to unauthorized access via Telnet, SSH, and FTP.
Recommendations:
For versions prior to 7.x, change the default credentials to unique and strong passwords to prevent unauthorized access. As a temporary workaround, consider restricting access to Telnet, SSH, and FTP services until the credentials are changed.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smartlan/G/Si