Unauthenticated Remote Attackers Have Full Control of Devices Due to Hard-Coded Passwords
CVE-2024-45275
9.8CRITICAL
What is CVE-2024-45275?
The vulnerability involves two hardcoded user accounts embedded within the firmware of the affected devices, accompanied by hardcoded passwords. This flaw enables an unauthenticated remote attacker to gain complete control over the devices, posing significant security risks. Organizations utilizing these devices should prioritize immediate remediation measures to safeguard their networks and systems.
Affected Version(s)
mbNET.mini 0.0.0 <= 2.2.13
REX100 0.0.0 <= 2.2.13
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Moritz Abrell
SySS GmbH
