MegaRAC Default Credentials Vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
In short
MegaRAC devices come with built-in usernames and passwords that are publicly known, allowing attackers to gain unauthorized access to system management interfaces. This is critical because anyone with internet access can potentially take control of these devices.
Technical detail
The vulnerability stems from hardcoded default credentials in MegaRAC BMC firmware (CWE-798). An unauthenticated attacker can access the web interface or IPMI services using known default credentials, bypassing authentication controls and gaining administrative privileges with no additional prerequisites.
Summary generated and translated by AI from the official description.
MegaRAC Default Credentials Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N