CVE-2019-25241

CRITICAL

FaceSentry Access Control System <6.4.8 - Privilege Escalation

Title source: llm

Description

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/47067

Scores

CVSS v3 9.8
EPSS 0.0049
EPSS Percentile 65.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (3)
iwt/facesentry_access_control_system_firmware 5.7.0
iwt/facesentry_access_control_system_firmware 5.7.2
iwt/facesentry_access_control_system_firmware 6.4.8
Published Dec 24, 2025
Tracked Since Feb 18, 2026