Unauthenticated Remote Attackers Have Full Control of Devices Due to Hard-Coded Passwords
CVE-2024-45275

9.8CRITICAL

Key Information:

Vendor
CVE Published:
15 October 2024

What is CVE-2024-45275?

The vulnerability involves two hardcoded user accounts embedded within the firmware of the affected devices, accompanied by hardcoded passwords. This flaw enables an unauthenticated remote attacker to gain complete control over the devices, posing significant security risks. Organizations utilizing these devices should prioritize immediate remediation measures to safeguard their networks and systems.

Affected Version(s)

mbNET.mini 0.0.0 <= 2.2.13

REX100 0.0.0 <= 2.2.13

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moritz Abrell
SySS GmbH
.
CVE-2024-45275 : Unauthenticated Remote Attackers Have Full Control of Devices Due to Hard-Coded Passwords