PT-2025-26661 · Unknown · Blue Angel Software Suite

Damiano Proietti

+2

·

Published

2025-06-24

·

Updated

2025-07-09

·

CVE-2025-34034

CVSS v4.0
9.3
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Name of the Vulnerable Software and Affected Versions:

Blue Angel Software Suite (affected versions not specified)

Description:

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-34034

Affected Products

Blue Angel Software Suite