PT-2025-7241 · Hirsch · Hirsch Enterphone Mesh
Eric Daigle
·
Published
2025-02-15
·
Updated
2025-03-13
·
CVE-2025-26793
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/MSI:S/S:P |
Name of the Vulnerable Software and Affected Versions:
Hirsch Enterphone MESH versions through 2024
Description:
The Web GUI configuration panel of Hirsch Enterphone MESH ships with default credentials,
username freedom and password viscount. The administrator is not prompted to change these credentials on initial configuration, and changing them requires many steps. Attackers can use the credentials over the Internet via "mesh.webadmin.MESHAdminServlet" to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' personally identifiable information (PII).Recommendations:
For Hirsch Enterphone MESH versions through 2024, change the default credentials as soon as possible, following the manufacturer's recommendations to secure the system. As a temporary workaround, consider restricting access to the "mesh.webadmin.MESHAdminServlet" endpoint until the default credentials are changed. Additionally, review and follow the manufacturer's guidelines for securing the Web GUI configuration panel to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hirsch Enterphone Mesh