CVE-2023-41030

MEDIUM

Juplink RX4-1500 <V1.0.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.

Scores

CVSS v3 6.3
EPSS 0.0011
EPSS Percentile 29.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-259 CWE-798
Status published
Products (1)
juplink/rx4-1500_firmware 1.0.2 - 1.0.5
Published Sep 18, 2023
Tracked Since Feb 18, 2026