Vulnerability Description
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-22543?
CVE-2026-22543 is a documented vulnerability. The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handl...
How severe is CVE-2026-22543?
CVSS scoring is not yet available for CVE-2026-22543. Check NVD for updates.
Is there a patch for CVE-2026-22543?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.