PT-2022-19803 · Usr · Usr Iot 4G Lte Industrial Cellular Vpn Router

Gjoko Krstic

·

Published

2022-05-27

·

Updated

2022-06-10

·

CVE-2022-29730

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions USR IOT 4G LTE Industrial Cellular VPN Router version 1.0.36
Description The issue concerns hard-coded credentials for the highest privileged account, which cannot be changed during normal device operation.
Recommendations For USR IOT 4G LTE Industrial Cellular VPN Router version 1.0.36, consider changing the default credentials as soon as possible if a method to do so becomes available, or contact the manufacturer for guidance on securing the device. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29730

Affected Products

Usr Iot 4G Lte Industrial Cellular Vpn Router