ZeroHour

CVE-2021-43284

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p31
Published
()
Modified
Description

An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).

Vendors
govicture
Products
wr1200 firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.