PT-2023-20642 · Usr · Usr-G806
Nikki2023
·
Published
2023-05-11
·
Updated
2024-05-17
·
CVE-2023-2645
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
USR USR-G806 version 1.0.41
Description
A critical issue was found in the Web Management Page component, where the manipulation of the
username/password argument with the input root leads to the use of a hard-coded password. This can be exploited remotely. The issue has been publicly disclosed and may be used for attacks. It is recommended to change the configuration settings.Recommendations
To resolve the issue, change the configuration settings for USR USR-G806 version 1.0.41. As a temporary workaround, consider restricting access to the Web Management Page until the issue is fully addressed. Avoid using the default
root input for the username/password argument to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Usr-G806