Default Factory Credentials with Administrative Access in HMS Networks Products
CVE-2026-32645
9.2CRITICAL
What is CVE-2026-32645?
A significant security risk exists within HMS Networks products due to the presence of default factory credentials that grant administrative access. These credentials are retained even after additional administrator accounts have been configured, allowing unauthorized users to exploit this vulnerability. This emphasizes the necessity for organizations to promptly change default credentials and ensure robust security practices to mitigate potential threats.
Affected Version(s)
700 Series 0
700 Series 0
700 Series 3.11.1
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabrianna (Ria) Milloway of Idaho National Laboratory reported this vulnerability to CISA.
