CVE-2022-36558

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
29/08/2022
Last modified:
02/09/2022

Description

Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:seiko-sol:skybridge_mb-a100_firmware:*:*:*:*:*:*:*:* 4.2.0 (including)
cpe:2.3:h:seiko-sol:skybridge_mb-a100:-:*:*:*:*:*:*:*
cpe:2.3:o:seiko-sol:skybridge_mb-a110_firmware:*:*:*:*:*:*:*:* 4.2.0 (including)
cpe:2.3:h:seiko-sol:skybridge_mb-a110:-:*:*:*:*:*:*:*