Hardcoded API Credentials in Barco wePresent WiPG-1600W Firmware
CVE-2020-28329
9.8CRITICAL
What is CVE-2020-28329?
The firmware of the Barco wePresent WiPG-1600W contains hardcoded API credentials, which can be exploited by malicious actors. By examining the firmware image, an attacker can discover the hardcoded account and password, enabling unauthorized access to administrative functions through the API. This security flaw highlights the importance of secure credential management and firmware integrity, affecting multiple versions of the product, including 2.5.1.8, 2.5.0.25, 2.5.0.24, and 2.4.1.19.