CVE-2022-24693

CRITICAL

Baicells Nova436Q & Neutrino 430 - Info Disclosure

Title source: llm

Description

Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

Exploits (1)

nomisec WRITEUP 3 stars
by lukejenkins · poc
https://github.com/lukejenkins/CVE-2022-24693

Scores

CVSS v3 9.8
EPSS 0.0227
EPSS Percentile 84.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (2)
baicells/neutrino_430_firmware < qrtb_2.7.8
baicells/nova436q_firmware < qrtb_2.7.8
Published Mar 30, 2022
Tracked Since Feb 18, 2026