PT-2024-33138 · Neye3C · Neye3C

Hankjames

·

Published

2024-10-24

·

Updated

2024-10-25

·

CVE-2024-48539

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Neye3C version 4.5.2.0
Description A hardcoded encryption key was found in the firmware update mechanism, which could potentially be exploited.
Recommendations For version 4.5.2.0, consider updating the firmware to a version that does not contain the hardcoded encryption key, if such an update becomes available. As a temporary workaround, restrict access to the firmware update mechanism to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-48539

Affected Products

Neye3C