CVE-2025-46352

Severity CVSS v4.0:
CRITICAL
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
30/05/2025
Last modified:
30/05/2025

Description

The CS5000 Fire Panel is vulnerable due to a hard-coded password that <br /> runs on a VNC server and is visible as a string in the binary <br /> responsible for running VNC. This password cannot be altered, allowing <br /> anyone with knowledge of it to gain remote access to the panel. Such <br /> access could enable an attacker to operate the panel remotely, <br /> potentially putting the fire panel into a non-functional state and <br /> causing serious safety issues.