Hardcoded API Credentials in Barco wePresent WiPG-1600W Firmware
CVE-2020-28329

9.8CRITICAL

Key Information:

Vendor

Barco

Vendor
CVE Published:
24 November 2020

What is CVE-2020-28329?

The firmware of the Barco wePresent WiPG-1600W contains hardcoded API credentials, which can be exploited by malicious actors. By examining the firmware image, an attacker can discover the hardcoded account and password, enabling unauthorized access to administrative functions through the API. This security flaw highlights the importance of secure credential management and firmware integrity, affecting multiple versions of the product, including 2.5.1.8, 2.5.0.25, 2.5.0.24, and 2.4.1.19.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.