CRITICAL · 9.8

CVE-2022-24693

Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The cre...

Vulnerability Description

Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BaicellsNova436Q Firmware<= qrtb_2.7.8
BaicellsNova436Q-
BaicellsNeutrino 430 Firmware<= qrtb_2.7.8
BaicellsNeutrino 430-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-24693?

CVE-2022-24693 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The cre...

How severe is CVE-2022-24693?

CVE-2022-24693 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-24693?

Check the references section above for vendor advisories and patch information. Affected products include: Baicells Nova436Q Firmware, Baicells Nova436Q, Baicells Neutrino 430 Firmware, Baicells Neutrino 430.