CVE-2018-17771

MEDIUM

Ingenico Telium 2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.

References (4)

Core 4
Core References
Exploit, Third Party Advisory x_refsource_misc
https://youtu.be/gtbS3Gr264w
Exploit, Third Party Advisory x_refsource_misc
https://youtu.be/oyUD7RDJsJs

Scores

CVSS v3 6.6
EPSS 0.0048
EPSS Percentile 37.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
ingenico/telium_2_firmware < 9.32.03
Published Sep 09, 2020
Tracked Since Feb 18, 2026