Hard Coded Password Vulnerability in Contec FXA3200 Wireless LAN Manager
CVE-2022-36159

8.8HIGH

Key Information:

Vendor

Contec

Vendor
CVE Published:
26 September 2022

What is CVE-2022-36159?

The Contec FXA3200 model, specifically versions 1.13 and below, is affected by a significant security flaw where a hard coded hash password for the root user is present in the /etc/shadow file. Due to the weak strength of this password, it can be compromised within minutes, allowing attackers to gain unauthorized access to the Wireless LAN Manager interface. Once inside, a malicious user can open the telnet port, which poses a risk of traffic sniffing and the potential to inject malware into the network.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.