7.8
CVSSv2

CVE-2022-24693

Published: 30/03/2022 Updated: 07/04/2022
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote malicious users to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

baicells nova436q_firmware

baicells neutrino_430_firmware

Github Repositories

CVE-2022-24693 Description Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 278 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh (The credentials are stored in the firmware, encrypted by the crypt function) CVSS Score This will be determined by the CNA that I am working with, but here is