Carlo Gavazzi EOS Box Hard-Coded Credentials
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 1.5%
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
nono source reports it
The Carlo Gavazzi
EOS-Box
stores hard-coded passwords in the PHP file of
the device. By using the hard-coded passwords, attackers can log into
the device with administrative privileges. This could allow the attacker
to have unauthorized access.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
Carlo Gavazzi Automation · EOS-Box