PT-2024-13710 · Device · Device
Robert Pogorzelski
·
Published
2024-01-12
·
Updated
2025-06-11
·
CVE-2023-49253
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Device (affected versions not specified)
Description
The root user password is hardcoded into the device and cannot be changed in the user interface. Additionally, there is an issue where a user's browser may be forced to execute JavaScript and pass the authentication cookie to an attacker, leveraging an XSS vulnerability located at "/gui/terminal tool.cgi" in the
data parameter.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Device