MegaRAC Default Credentials Vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.3epss 0.6%
exploitation probability
0.6%top 50% of all CVEs
observed exploitation
nono source reports it
In short
MegaRAC devices come with default usernames and passwords that are not changed during installation. An attacker with network access can use these credentials to log in and take full control of the device.
Technical detail
CWE-798 hardcoded credentials in MegaRAC BMC allow unauthenticated network-based attackers to gain administrative access without modification of default credentials. Pre-condition requires network connectivity to the management interface; impact includes full system compromise and remote code execution.
Summary generated and translated by AI from the official description.
MegaRAC Default Credentials Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H