CVE-2019-25241
CRITICALFaceSentry Access Control System <6.4.8 - Privilege Escalation
Title source: llmDescription
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/47067
Scores
CVSS v3
9.8
EPSS
0.0049
EPSS Percentile
65.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (3)
iwt/facesentry_access_control_system_firmware
5.7.0
iwt/facesentry_access_control_system_firmware
5.7.2
iwt/facesentry_access_control_system_firmware
6.4.8
Published
Dec 24, 2025
Tracked Since
Feb 18, 2026