CVE-2026-69657
—Default Password Enables Login to XING CPTrans-ME-X Devices
XING CPTrans-ME-X devices are affected by a use-of-default-password flaw (CWE-1393): the device accepts login with a factory-set credential that is not unique per installation. An attacker who knows this default credential can authenticate over the network with no prior privileges and no user interaction. Once logged in, the attacker gains full control of the device — the CVSS 4.0 base score of 9.3 reflects high impact to the device's confidentiality, integrity, and availability, meaning it can be reconfigured, tampered with, or disrupted. Any deployed CPTrans-ME-X unit whose default password has not been changed is affected; the available data does not specify affected version ranges or a fixed version. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Immediately change the default password on any CPTrans-ME-X device and verify the factory credential no longer grants access; restrict the device's login/management interface to trusted networks and do not expose it to the internet. Monitor the vendor and JPCERT advisories for a firmware update, since no fixed version is specified in the available data.
| XING CPTrans-ME-X | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.
- Weakness
- CWE-1393
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.