A remote unauthenticated attacker can use the firmware...
High severity
Unreviewed
Published
Aug 13, 2024
to the GitHub Advisory Database
•
Updated Aug 22, 2025
Description
Published by the National Vulnerability Database
Aug 13, 2024
Published to the GitHub Advisory Database
Aug 13, 2024
Last updated
Aug 22, 2025
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
References