vendor:
Multiple Products
by:
LiquidWorm
9.8
CVSS
HIGH
Default Hardcoded Credentials Remote Root
798
CWE
Product Name: Multiple Products
Affected Version From: SignEdje Digital Signage Player v2.08.28
Affected Version To: adManage Traffic & Media Management Application v2.5.4
Patch Exists: YES
Related CWE: N/A
CPE: a:adtec_digital:multiple_products
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: GNU/Linux 4.1.8 (armv7l), GNU/Linux 3.12.38 (PowerPC), GNU/Linux 2.6.14 (PowerPC), Adtec Embedded Linux 0.9 (fido), Apache
2020
Adtec Digital Multiple Products – Default Hardcoded Credentials Remote Root
The devices utilizes hard-coded and default credentials within its Linux distribution image for Web/Telnet/SSH access. A remote attacker could exploit this vulnerability by logging in using the default credentials for accessing the web interface or gain shell access as root.
Mitigation:
Change the default credentials and restrict access to the web interface and shell access.