vendor:
Raspberry Pi OS
by:
netspooky
9.8
CVSS
CRITICAL
Default Credentials
287
CWE
Product Name: Raspberry Pi OS
Affected Version From: Raspberry Pi OS <= 5.10
Affected Version To: Raspberry Pi OS <= 5.10
Patch Exists: NO
Related CWE: CVE-2021-38759
CPE: o:raspberrypi:raspberry_pi_os
Platforms Tested: Raspberry Pi OS 5.10
2021
Raspberry Pi 5.10 – Default Credentials
This exploit is used to gain access to a Raspberry Pi OS <= 5.10 device using the default credentials (username: pi, password: raspberry). The exploit is written in Python and uses the Paramiko library to connect to the device and execute the 'id' command.
Mitigation:
Change the default credentials of the device.