ZeroHour

CVE-2019-3950

CVSS 3.0
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.

Vendors
arlo
Products
vmb3010 firmware, vmb4000 firmware, vmb3500 firmware, vmb4500 firmware, vmb5000 firmware
Weakness
CWE-798
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.