PT-2025-6758 · Ixon B.V. · Ixrouter Ix2400

Marcel Rick-Cen

·

Published

2025-02-14

·

Updated

2025-02-14

·

CVE-2024-57790

CVSS v3.1

5.4

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) version 3.0
Description The issue concerns hardcoded root credentials stored in the non-volatile flash memory. This allows physically proximate attackers to gain root access via UART or SSH.
Recommendations For version 3.0, consider changing the hardcoded root credentials to unique, secure credentials to prevent unauthorized access. As a temporary workaround, restrict physical access to the device and limit SSH and UART connections to trusted sources until a patch is available.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-57790

Affected Products

Ixrouter Ix2400