CVE-2022-3203

CRITICAL

ORing IAP-420+ Firmware 2.0m - Hardcoded Telnet Credentials

Title source: manual
STIX 2.1

Description

On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative shell. These credentials are reset to defaults with every reboot.

References (1)

Core 1
Core References
Exploit, Mitigation, Third Party Advisory
https://mads.uniud.it/2022/09/lord-of-the-orings/

Scores

CVSS v3 9.8
EPSS 0.0085
EPSS Percentile 53.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-912
Status published
Products (2)
oringnet/iap-420\+_firmware 2.0m
oringnet/iap-420_firmware 2.0m
Published Oct 21, 2022
Tracked Since Feb 18, 2026