8.7
CVE-2026-32965
- EPSS 0.35%
- Veröffentlicht 20.04.2026 03:17:33
- Zuletzt bearbeitet 22.04.2026 17:29:52
- CVE-Watchlists
- Unerledigt
Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Silextechnology ≫ Sd-330ac Firmware Version < 1.50
Silextechnology ≫ Amc Manager Version < 5.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.263 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| JP CERT | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| JP CERT | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-1188 Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.silex.jp/support/security-advisories/en/2026-001
https://www.silex.jp/support/security-advisories/2026-001
https://jvn.jp/en/vu/JVNVU94271449/