CVE-2025-46352
Severity CVSS v4.0:
CRITICAL
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
30/05/2025
Last modified:
30/05/2025
Description
The CS5000 Fire Panel is vulnerable due to a hard-coded password that <br />
runs on a VNC server and is visible as a string in the binary <br />
responsible for running VNC. This password cannot be altered, allowing <br />
anyone with knowledge of it to gain remote access to the panel. Such <br />
access could enable an attacker to operate the panel remotely, <br />
potentially putting the fire panel into a non-functional state and <br />
causing serious safety issues.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL



