PT-2023-20642 · Usr · Usr-G806

Nikki2023

·

Published

2023-05-11

·

Updated

2024-05-17

·

CVE-2023-2645

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions USR USR-G806 version 1.0.41
Description A critical issue was found in the Web Management Page component, where the manipulation of the username/password argument with the input root leads to the use of a hard-coded password. This can be exploited remotely. The issue has been publicly disclosed and may be used for attacks. It is recommended to change the configuration settings.
Recommendations To resolve the issue, change the configuration settings for USR USR-G806 version 1.0.41. As a temporary workaround, consider restricting access to the Web Management Page until the issue is fully addressed. Avoid using the default root input for the username/password argument to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-2645

Affected Products

Usr-G806