CVE-2019-25241

CRITICAL

FaceSentry Access Control System <6.4.8 - Privilege Escalation

Title source: llm

Description

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/47067

Scores

CVSS v3 9.8
EPSS 0.0042
EPSS Percentile 61.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-798
Status published

Affected Products (3)

iwt/facesentry_access_control_system_firmware
iwt/facesentry_access_control_system_firmware
iwt/facesentry_access_control_system_firmware

Timeline

Published Dec 24, 2025
Tracked Since Feb 18, 2026