vendor:
Lync:Mac firmware
by:
maj0rmil4d - Ali Jalalat
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: Lync:Mac firmware
Affected Version From: Lync:Mac firmware 1.0.1
Affected Version To: Lync:Mac firmware 1.0.1, likely earlier versions
Patch Exists: NO
Related CWE: CVE-2020-17456
CPE: o:seowonintech:lync:mac_firmware:1.0.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 - Parrot sec
2020
Seowon SlC 130 Router – Remote Code Execution
A user can run arbitrary commands on the router as root due to hardcoded credentials. The credentials are VIP/V!P83869000, Root/PWDd0N~WH*4G#DN, root/gksrmf28, and admin/admin.
Mitigation:
Remove the hardcoded credentials and use strong passwords.