Hard-Coded Credentials Vulnerability in MR-GM5L-S1 and MR-GM5A-L1 by MRL
CVE-2026-24448

9.3CRITICAL

Key Information:

Vendor
CVE Published:
11 March 2026

What is CVE-2026-24448?

A security vulnerability has been identified in devices MR-GM5L-S1 and MR-GM5A-L1 that involves hard-coded credentials. This issue allows attackers to potentially gain unauthorized administrative access, posing a significant security risk. Users of these products are advised to take prompt action to mitigate this vulnerability by updating to secure versions and following best practices for credential management.

Affected Version(s)

MR-GM5A-L1 firmware versions prior to v2.01.04N1_02

MR-GM5L-S1 firmware versions prior to v2.01.04N1_02

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.