CVE-2019-25241
CRITICALFaceSentry Access Control System <6.4.8 - Privilege Escalation
Title source: llmDescription
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/47067
Scores
CVSS v3
9.8
EPSS
0.0042
EPSS Percentile
61.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-798
Status
published
Affected Products (3)
iwt/facesentry_access_control_system_firmware
iwt/facesentry_access_control_system_firmware
iwt/facesentry_access_control_system_firmware
Timeline
Published
Dec 24, 2025
Tracked Since
Feb 18, 2026