CVE-2024-5947

MEDIUM NUCLEI

Deep Sea Electronics DSE855 Firmware - Unauthenticated Information Disclosure via Configuration Backup

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-5947. PoCs published by Cappricio-Securities. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a scanner for CVE-2024-5947, which targets an authentication bypass vulnerability in Deep Sea Electronics DSE855. The tool checks for vulnerable endpoints and reports findings via Telegram if configured.

Description

Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-22679.

Exploits (1)

nomisec SCANNER
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2024-5947

This repository contains a scanner for CVE-2024-5947, which targets an authentication bypass vulnerability in Deep Sea Electronics DSE855. The tool checks for vulnerable endpoints and reports findings via Telegram if configured.

Classification
Scanner 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Deep Sea Electronics DSE855
No auth needed
Prerequisites: Network access to the target device · List of URLs or a single URL to scan
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Deep Sea Electronics DSE855 - Authentication Bypass
MEDIUMVERIFIEDby s4e-io
FOFA: Deep Sea Electronics

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_research-advisory
https://www.zerodayinitiative.com/advisories/ZDI-24-671/

Scores

CVSS v3 6.5
EPSS 0.0242
EPSS Percentile 82.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
deepseaelectronics/dse855_firmware 1.1.0
Published Jun 13, 2024
Tracked Since Feb 18, 2026