Vulnerability Description
INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/172838
- https://packetstormsecurity.com/files/155618
- https://www.exploit-db.com/exploits/47763
- https://www.inim.biz/
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5546.php
FAQ
What is CVE-2019-25291?
CVE-2019-25291 is a vulnerability with a CVSS score of 7.5 (HIGH). INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these pe...
How severe is CVE-2019-25291?
CVE-2019-25291 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25291?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.