CVE-2022-47558
CRITICALOrmazabal ekorRCI and ekorCCP Firmware - Unauthenticated FTP Access via Default Credentials
Title source: llmDescription
Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify configuration files, install rootkits or backdoors.
References (1)
Core 1
Core References
Scores
CVSS v3
9.4
EPSS
0.0052
EPSS Percentile
39.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-284
CWE-798
Status
published
Products (2)
ormazabal/ekorccp_firmware
601j
ormazabal/ekorrci_firmware
601j
Published
Sep 19, 2023
Tracked Since
Feb 18, 2026