peter bassill · operator
$ cve CVE-2022-24693 JSON

CVE-2022-24693

9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.34% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2022-03-30
Last modified2026-06-17

Affected (4)

VendorProduct
baicellsneutrino 430
baicellsneutrino 430 firmware
baicellsnova436q
baicellsnova436q firmware

References

→ the Explorer  ·  watch your stack  ·  NVD