CVE-2021-32535

CRITICAL

QSAN SANOS < 2.1.0 - Unauthenticated Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4892-768d9-1.html

Scores

CVSS v3 9.8
EPSS 0.0141
EPSS Percentile 69.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
qsan/sanos < 2.1.0
Published Jul 07, 2021
Tracked Since Feb 18, 2026