CVE-2021-37555

CRITICAL

TX9 Automatic Food Dispenser Firmware - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g., tar and nc).

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-296520

Scores

CVSS v3 9.8
EPSS 0.0138
EPSS Percentile 68.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
trixie/tx9_automatic_food_dispenser_firmware 3.2.57
Published Jul 26, 2021
Tracked Since Feb 18, 2026