ZeroHour

CVE-2021-45877

CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.

Vendors
garo
Products
wallbox gtb firmware, wallbox gtc firmware, wallbox glb firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.