CVE-2018-5399

CRITICAL

Auto-Maskin DCU-210E and RP-210E Firmware < 3.7 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. The Dropbear server is configured with a hard-coded user name and password combination of root / amroot. The server is configured to use password only authentication not cryptographic keys, however the firmware image contains an RSA host-key for the server. An attacker can exploit this vulnerability to gain root access to the Angstrom Linux operating system and modify any binaries or configuration files in the firmware. Affected releases are Auto-Maskin DCU-210E RP-210E: Versions prior to 3.7 on ARMv7.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/176301

Scores

CVSS v3 9.4
EPSS 0.0209
EPSS Percentile 79.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Details

CWE
CWE-798
Status published
Products (2)
auto-maskin/dcu-210e_firmware < 3.7
auto-maskin/rp-210e_firmware < 3.7
Published Oct 08, 2018
Tracked Since Feb 18, 2026