PT-2022-11273 · Edimax · Edimax Ic-3140W
Published
2022-06-29
·
Updated
2022-07-11
·
CVE-2021-40597
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EDIMAX IC-3140W version 3.11
Description
The issue concerns the firmware of the EDIMAX IC-3140W, where the Administrator
username and password are hardcoded. This means that the credentials for administrative access are embedded directly into the firmware, potentially allowing unauthorized access.Recommendations
For EDIMAX IC-3140W version 3.11, consider changing the hardcoded Administrator
username and password to custom credentials as soon as possible to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edimax Ic-3140W