Hard-Coded Credential Vulnerability in INIM Electronics Smartliving Products
CVE-2019-25291
Key Information:
- Vendor
Inim Electronics S.r.l.
- Vendor
- CVE Published:
- 7 January 2026
Badges
What is CVE-2019-25291?
The INIM Electronics Smartliving SmartLAN/G/SI devices, running Linux versions up to 6.x, contain hard-coded credentials that are unchangeable through regular device operations. This vulnerability allows malicious actors to exploit these persistent credentials, facilitating unauthorized access to the system across various models of SmartLiving devices. As a result, attackers can gain complete control over the affected systems, leading to potential data breaches and further exploitation.
Affected Version(s)
Smartliving SmartLAN/G/SI <=6.x <= 6.x
Smartliving SmartLAN/G/SI 505
Smartliving SmartLAN/G/SI 515
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
