Insecure FTP Credentials in ShineLan-X Device Firmware
CVE-2025-36747
9.4CRITICAL
What is CVE-2025-36747?
The ShineLan-X firmware contains hardcoded credentials for FTP access, which can be exploited by attackers to establish an insecure connection. This vulnerability allows malicious actors to replace legitimate firmware files with their own unauthorized versions, as the signature verification for firmware updates is not enforced. As such, vulnerable devices may inadvertently deploy compromised firmware, leading to potential system breaches and data loss.
Affected Version(s)
ShineLan-X 3.6.0.0 <= 3.6.0.2
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Hamid Rahmouni
Victor Pasman
