vendor:
S3900-24T4S
by:
Daniele Linguaglossa & Alberto Bruscino
7.4
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: S3900-24T4S
Affected Version From: latest
Affected Version To: latest
Patch Exists: NO
Related CWE: CVE-2023-30350
CPE: h:fs:s3900-24t4s
Platforms Tested: latest
2023
FS-S3900-24T4S Privilege Escalation
This exploit allows an attacker to gain access to the FS-S3900-24T4S device by using the telnet protocol. The attacker can use the guest credentials to login and then use the enable command with the super password to gain access to the device. The attacker can then configure the device to create a new user with admin privileges and no password.
Mitigation:
Disable telnet access and use SSH instead. Use strong passwords for all accounts. Monitor the device for any suspicious activity.