CVE-2022-29730

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
02/06/2022
Last modified:
10/06/2022

Description

USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:usr:usr-g808_firmware:1.0.36:*:*:*:*:*:*:*
cpe:2.3:h:usr:usr-g808:-:*:*:*:*:*:*:*
cpe:2.3:o:usr:usr-g807_firmware:1.0.36:*:*:*:*:*:*:*
cpe:2.3:h:usr:usr-g807:-:*:*:*:*:*:*:*
cpe:2.3:o:usr:usr-g806_firmware:1.0.36:*:*:*:*:*:*:*
cpe:2.3:h:usr:usr-g806:-:*:*:*:*:*:*:*
cpe:2.3:o:usr:usr-g800v2_firmware:1.0.36:*:*:*:*:*:*:*
cpe:2.3:h:usr:usr-g800v2:-:*:*:*:*:*:*:*
cpe:2.3:o:usr:usr-lg220-l_firmware:1.2.7:*:*:*:*:*:*:*
cpe:2.3:h:usr:usr-lg220-l:-:*:*:*:*:*:*:*