ZeroHour

CVE-2021-27372

CVSS 3.1
9.8 critical
EPSS
2%p75
Published
()
Modified
Description

Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.

Vendors
realtek
Products
xpon rtl9601d software development kit
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.