PT-2025-7241 · Hirsch · Hirsch Enterphone Mesh

Eric Daigle

·

Published

2025-02-15

·

Updated

2025-03-13

·

CVE-2025-26793

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/MSI:S/S:P
Name of the Vulnerable Software and Affected Versions: Hirsch Enterphone MESH versions through 2024
Description: The Web GUI configuration panel of Hirsch Enterphone MESH ships with default credentials, username freedom and password viscount. The administrator is not prompted to change these credentials on initial configuration, and changing them requires many steps. Attackers can use the credentials over the Internet via "mesh.webadmin.MESHAdminServlet" to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' personally identifiable information (PII).
Recommendations: For Hirsch Enterphone MESH versions through 2024, change the default credentials as soon as possible, following the manufacturer's recommendations to secure the system. As a temporary workaround, consider restricting access to the "mesh.webadmin.MESHAdminServlet" endpoint until the default credentials are changed. Additionally, review and follow the manufacturer's guidelines for securing the Web GUI configuration panel to prevent unauthorized access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26793

Affected Products

Hirsch Enterphone Mesh