← back
CVE-2022-40259highCWE-798

MegaRAC Default Credentials Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.3epss 0.6%
exploitation probability
0.6%top 50% of all CVEs
observed exploitation
nono source reports it
In short

MegaRAC devices come with default usernames and passwords that are not changed during installation. An attacker with network access can use these credentials to log in and take full control of the device.

Technical detail

CWE-798 hardcoded credentials in MegaRAC BMC allow unauthenticated network-based attackers to gain administrative access without modification of default credentials. Pre-condition requires network connectivity to the management interface; impact includes full system compromise and remote code execution.

Summary generated and translated by AI from the official description.
MegaRAC Default Credentials Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H