CVE-2022-40259
MegaRAC Default Credentials Vulnerability
In short
MegaRAC devices come with default usernames and passwords that are not changed during installation. An attacker with network access can use these credentials to log in and take full control of the device.
Technical detail
CWE-798 hardcoded credentials in MegaRAC BMC allow unauthenticated network-based attackers to gain administrative access without modification of default credentials. Pre-condition requires network connectivity to the management interface; impact includes full system compromise and remote code execution.
Summary generated and translated by AI from the official description.
MegaRAC Default Credentials Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →