Plaintext Password Vulnerability in Realtek xPON RTL9601D SDK
CVE-2021-27372

9.8CRITICAL

Key Information:

Vendor

Realtek

Vendor
CVE Published:
25 March 2021

What is CVE-2021-27372?

The Realtek xPON RTL9601D SDK version 1.9 contains a vulnerability where sensitive passwords are stored in plaintext. This security flaw may allow attackers to leverage the built-in network monitoring tool to gain unauthorized access to the device, potentially executing arbitrary commands with root permissions. Organizations using this SDK should address this vulnerability immediately to safeguard their systems from exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.