CVE-2019-25241
Severity CVSS v4.0:
CRITICAL
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
24/12/2025
Last modified:
24/12/2025
Description
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
7.50
Severity 3.x
HIGH



