10

CVE-2018-12526

Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TelesquareSdt-cs3b1 Firmware Version <= 1.2.0
   TelesquareSdt-cs3b1 Version-
TelesquareSdt-cw3b1 Firmware Version <= 1.2.0
   TelesquareSdt-cw3b1 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.3% 0.81
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=27284
Third Party Advisory
https://www.fortiguard.com/zeroday/FG-VD-18-106
Third Party Advisory