← volver
CVE-2025-34034criticalexplotación observadaCWE-798

5VTechnologies Blue Angel Software Suite Hardcoded Credentials

50Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck.

ssvc Actcvss 9.3epss 0.6%
de la publicación al arma
Publicada en NVD24 jun
VulnCheck23 jun
probabilidad de explotación
0.6%top 52% de las CVE
explotación observada
VulnCheck
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-26 UTC.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N