PT-2025-54425 · Cypress Solutions · Cypress Solutions Ctm-200 +1

Published

2025-12-31

·

Updated

2026-01-01

·

CVE-2021-47744

CVSS v3.1
7.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cypress Solutions CTM-200/CTM-ONE version 1.3.6
Description The software contains a hard-coded credential issue in its Linux distribution, exposing root access. An attacker can exploit the static password 'Chameleon' to gain remote root access via Telnet or SSH on affected devices.
Recommendations Change the default 'Chameleon' password to a strong, unique password. Disable Telnet access and rely on SSH for remote administration. Restrict SSH access to authorized users and networks.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-47744

Affected Products

Cypress Solutions Ctm-200
Cypress Solutions Ctm-One