vendor:
SmartLiving SmartLAN/G/SI
by:
LiquidWorm
8.8
CVSS
HIGH
Hard-coded Credentials
522
CWE
Product Name: SmartLiving SmartLAN/G/SI
Affected Version From: <=6.x
Affected Version To: <=6.x
Patch Exists: YES
Related CWE: N/A
CPE: h:inim_electronics:smartliving_smartlan_g_si
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
Inim Electronics Smartliving SmartLAN 6.x – Hard-coded Credentials
Inim Electronics SmartLiving SmartLAN/G/SI <=6.x is vulnerable to hard-coded credentials. The SmartLAN/G/SI board contains hard-coded credentials that can be used to gain access to the system. The credentials are stored in plain text in the board's memory and can be accessed by anyone with physical access to the board.
Mitigation:
The vendor has released a patch to address this vulnerability.