10

CVE-2013-3542

Exploit
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with the same password, which makes it easier for remote attackers to obtain access via a TELNET session.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrandstreamGxv3501 Firmware Version1.0.4.11
   GrandstreamGxv3501 Version-
GrandstreamGxv3504 Firmware Version1.0.4.11
   GrandstreamGxv3504 Version-
GrandstreamGxv3601 Firmware Version1.0.4.11
   GrandstreamGxv3601 Version-
GrandstreamGxv3601hd Firmware Version1.0.4.11
   GrandstreamGxv3601hd Version-
GrandstreamGxv3601ll Firmware Version1.0.4.11
   GrandstreamGxv3601ll Version-
GrandstreamGxv3611hd Firmware Version1.0.4.11
   GrandstreamGxv3611hd Version-
GrandstreamGxv3611ll Firmware Version1.0.4.11
   GrandstreamGxv3611ll Version-
GrandstreamGxv3615w Firmware Version1.0.4.11
   GrandstreamGxv3615w Version-
GrandstreamGxv3615p Firmware Version1.0.4.11
   GrandstreamGxv3615p Version-
GrandstreamGxv3651fhd Firmware Version1.0.4.11
   GrandstreamGxv3651fhd Version-
GrandstreamGxv3662hd Firmware Version1.0.4.11
   GrandstreamGxv3662hd Version-
GrandstreamGxv3615wp Hd Firmware Version1.0.4.11
   GrandstreamGxv3615wp Hd Version-
GrandstreamGxv3500 Firmware Version1.0.4.11
   GrandstreamGxv3500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.24% 0.864
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.