ZeroHour

CVE-2026-70403

Hard-coded Password Allows Remote Login to XING CPTrans-ME-X Devices

CVSS 4.0
9.3 critical
EPSS
<1%p22
Published
()
Modified
AI analysis

XING CPTrans-ME-X devices ship with a hard-coded (built-in) password, meaning a fixed credential is embedded in the product rather than uniquely set per installation (CWE-259). An attacker who knows or obtains this credential can authenticate to the device over the network with no privileges and no user interaction, per the CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N). Once logged in, the attacker has high impact on the device's confidentiality, integrity, and availability, such as viewing or modifying its configuration or disrupting its operation, which drives the critical 9.3 CVSS 4.0 score. Affected users are any operators running the XING CPTrans-ME-X device; the advisory data does not specify affected version ranges, so any unit shipped with the built-in credential should be assumed affected. There are no known public proofs of concept, the issue is not in the CISA KEV catalog, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days, indicating no known exploitation at this time.

What to do: Check whether CPTrans-ME-X devices in your environment are reachable from untrusted networks, and restrict management access with firewall rules or ACLs; if the device supports it, change or rotate the built-in password immediately. Watch for a vendor (XING) or JPCERT advisory offering firmware with the hard-coded credential removed or randomized, and upgrade when a fixed version is released. Review device logs for unexpected logins using the built-in account.

Affected
XING CPTrans-ME-X
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

Weakness
CWE-259
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.