vendor:
WEMS BEMS 21.3.1
by:
LiquidWorm
8.8
CVSS
HIGH
Undocumented Backdoor Account
N/A
CWE
Product Name: WEMS BEMS 21.3.1
Affected Version From: Web: 21.3.1
Affected Version To: Firmware: 1.18.0.3 (OS: i686-1.1)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Shockwave Flash (SWF) / CGI
2019
Exploit: WEMS BEMS 21.3.1 – Undocumented Backdoor Account
The wireless BMS solution has an undocumented backdoor account that is Base64-encoded. These sets of credentials are never exposed to the end-user and cannot be changed through any normal operation of the controller thru the RMI. Attacker could exploit this vulnerability by logging in using the backdoor account with highest privileges for administration and gain full system control.
Mitigation:
Disable the backdoor account and use strong authentication methods.