vendor:
MultiHaul TG series
by:
semaja2
6.1
CVSS
HIGH
Credential Disclosure
798
CWE
Product Name: MultiHaul TG series
Affected Version From: Version < 2.0.0
Affected Version To: Version < 2.0.0
Patch Exists: NO
Related CWE:
CPE: a:siklu:multihaultg_firmware:<2.0.0
Platforms Tested:
2024
Siklu MultiHaul TG series – Unauthenticated Credential Disclosure
The Siklu MultiHaul TG series with a version less than 2.0.0 allows unauthenticated credential disclosure. By exploiting this vulnerability, an attacker can obtain random generated username and password, gaining unauthorized access to the device.
Mitigation:
Update to version 2.0.0 or higher to mitigate this vulnerability. Additionally, restrict network access to the device to trusted hosts only.