CVE-2021-27440

CRITICAL

Reason DR60 <02A04.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).

Scores

CVSS v3 9.8
EPSS 0.0027
EPSS Percentile 50.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-259 CWE-798
Status published
Products (1)
ge/reason_dr60_firmware < 02a04.1
Published Mar 25, 2021
Tracked Since Feb 18, 2026