CVE-2020-21995
CRITICALInim Smartliving Firmware < 6.0 - Use of Hard-coded Credentials
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-21995. PoCs published by LiquidWorm.
AI-analyzed exploit summary This writeup discloses hard-coded credentials in Inim Electronics Smartliving SmartLAN/G/SI devices (versions <=6.x). The credentials are embedded in the Linux distribution image and cannot be changed by the end-user, allowing attackers to gain unauthorized system access via Telnet, SSH, or FTP.
Description
Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.
Exploits (1)
This writeup discloses hard-coded credentials in Inim Electronics Smartliving SmartLAN/G/SI devices (versions <=6.x). The credentials are embedded in the Linux distribution image and cannot be changed by the end-user, allowing attackers to gain unauthorized system access via Telnet, SSH, or FTP.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H