CVE-2012-2441

RuggedCom ROS <3.3 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-2441. PoCs published by jc.

AI-analyzed exploit summary The exploit reveals an undocumented backdoor account in RuggedCom's Rugged Operating System (ROS) with a dynamically generated password based on the device's MAC address. The provided Perl script calculates the password, allowing unauthorized access to the 'factory' account.

Description

RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH or (2) HTTPS session, a different vulnerability than CVE-2012-1803.

Exploits (1)

exploitdb WORKING POC
by jc · textremotehardware
https://www.exploit-db.com/exploits/18779

The exploit reveals an undocumented backdoor account in RuggedCom's Rugged Operating System (ROS) with a dynamically generated password based on the device's MAC address. The provided Perl script calculates the password, allowing unauthorized access to the 'factory' account.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: RuggedCom Rugged Operating System (ROS) (all versions)
No auth needed
Prerequisites: Device MAC address
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory x_refsource_misc
http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/889195
Broken Link, Vendor Advisory x_refsource_confirm
http://www.ruggedcom.com/productbulletin/ros-security-page/
Broken Link, Third Party Advisory, US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75244
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2012/Apr/277

Scores

EPSS 0.0861
EPSS Percentile 94.4%

Details

CWE
CWE-521
Status published
Products (1)
siemens/ruggedcom_rugged_operating_system < 3.3.0
Published Apr 28, 2012
Tracked Since Feb 18, 2026