QSAN Storage Manager - Use of Hard-coded Password-2
No sign of exploitation. No public exploitation artifact known so far.
QSAN Storage Manager contains a hard-coded password in its firmware that allows anyone to log in as an administrator and execute dangerous system commands. This is a critical flaw because attackers can remotely take full control of the storage system.
The vulnerability exists in QSAN Storage Manager firmware due to a hard-coded debug mode password embedded in the application. Remote attackers can authenticate to the control interface with administrator privileges and execute arbitrary system instructions without proper authorization, bypassing authentication mechanisms. Exploitation requires network access to the affected service and knowledge of the hard-coded credential.