CVE-2021-47744
HIGHCypress Solutions CTM-200/CTM-ONE <1.3.6 - Code Injection
Title source: llmDescription
Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on affected devices.
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/50407
References (4)
Scores
CVSS v3
7.5
EPSS
0.0005
EPSS Percentile
14.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-798
Status
draft
Timeline
Published
Dec 31, 2025
Tracked Since
Feb 18, 2026