CVE-2023-47213

CRITICAL

First Corporation DVRs - Unauthenticated Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.

Scores

CVSS v3 9.8
EPSS 0.0109
EPSS Percentile 61.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (28)
c-first/cfr-1004ea_firmware
c-first/cfr-1008ea_firmware
c-first/cfr-1016ea_firmware
c-first/cfr-16eaa_firmware
c-first/cfr-16eab_firmware
c-first/cfr-16eha_firmware
c-first/cfr-16ehd_firmware
c-first/cfr-4eaa_firmware
c-first/cfr-4eaam_firmware
c-first/cfr-4eab_firmware
... and 18 more
Published Nov 16, 2023
Tracked Since Feb 18, 2026