CVE-2021-29255
HIGHMicroseven Mym71080i-b Firmware - Insufficiently Protected Credentials
Title source: ruleDescription
MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same network as the device can capture these credentials.
Scores
CVSS v3
7.5
EPSS
0.0011
EPSS Percentile
30.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
Status
published
Affected Products (1)
microseven/mym71080i-b_firmware
< 2.0.20
Timeline
Published
Mar 26, 2021
Tracked Since
Feb 18, 2026