CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
68.8%
On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative shell. These credentials are reset to defaults with every reboot.
Vendor | Product | Version | CPE |
---|---|---|---|
oringnet | iap-420\+_firmware | 2.0m | cpe:2.3:o:oringnet:iap-420\+_firmware:2.0m:*:*:*:*:*:*:* |
oringnet | iap-420\+ | - | cpe:2.3:h:oringnet:iap-420\+:-:*:*:*:*:*:*:* |
oringnet | iap-420_firmware | 2.0m | cpe:2.3:o:oringnet:iap-420_firmware:2.0m:*:*:*:*:*:*:* |
oringnet | iap-420 | - | cpe:2.3:h:oringnet:iap-420:-:*:*:*:*:*:*:* |