The certificate and private key used for providing...
Moderate severity
Unreviewed
Published
May 21, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
May 21, 2025
Published to the GitHub Advisory Database
May 21, 2025
The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware and are shipped with the update files. An attacker can use the private key to perform man-in-the-middle attacks against users of the admin interface. The files are located in /etc/ssl (e.g. salia.local.crt, salia.local.key and salia.local.pem). There is no option to upload/configure custom TLS certificates.
References