9.8
CVE-2019-25241
- EPSS 0.65%
- Veröffentlicht 24.12.2025 19:27:58
- Zuletzt bearbeitet 31.12.2025 14:15:50
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
FaceSentry Access Control System 6.4.8 Remote SSH Root Access
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iwt ≫ Facesentry Access Control System Firmware Version5.7.0
Iwt ≫ Facesentry Access Control System Firmware Version5.7.2
Iwt ≫ Facesentry Access Control System Firmware Version6.4.8
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.65% | 0.464 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
https://www.exploit-db.com/exploits/47067
http://www.iwt.com.hk
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5526.php