ZeroHour

CVE-2026-69657

Default Password Enables Login to XING CPTrans-ME-X Devices

CVSS 4.0
9.3 critical
EPSS
<1%p22
Published
()
Modified
AI analysis

XING CPTrans-ME-X devices are affected by a use-of-default-password flaw (CWE-1393): the device accepts login with a factory-set credential that is not unique per installation. An attacker who knows this default credential can authenticate over the network with no prior privileges and no user interaction. Once logged in, the attacker gains full control of the device — the CVSS 4.0 base score of 9.3 reflects high impact to the device's confidentiality, integrity, and availability, meaning it can be reconfigured, tampered with, or disrupted. Any deployed CPTrans-ME-X unit whose default password has not been changed is affected; the available data does not specify affected version ranges or a fixed version. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Immediately change the default password on any CPTrans-ME-X device and verify the factory credential no longer grants access; restrict the device's login/management interface to trusted networks and do not expose it to the internet. Monitor the vendor and JPCERT advisories for a firmware update, since no fixed version is specified in the available data.

Affected
XING CPTrans-ME-X
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

Weakness
CWE-1393
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.