Predictable Password Vulnerability in E3 Site Supervisor Firmware by Armis
CVE-2025-6519
What is CVE-2025-6519?
The E3 Site Supervisor, running firmware versions earlier than 2.31F01, is vulnerable due to the presence of a default admin user named 'ONEDAY' that comes with a password generated daily based on a predictable algorithm. This predictability allows an attacker to easily deduce the admin password, compromising the security of the device and potentially leading to unauthorized access. Notably, the ONEDAY user account cannot be deleted or modified by any user, exacerbating the vulnerability and leaving systems exposed to attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
E3 Supervisory Control 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
