Hirsch Enterphone MESH是Hirsch公司的一款基于MESH网络技术的智能门禁和通信系统。 Hirsch Enterphone MESH 2024及之前版本存在安全漏洞,该漏洞源于默认凭据未强制修改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hirsch | Enterphone MESH | 0 ~ 2024 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' PII. NOTE- the Supplier's perspective is that the "vulnerable systems are not following manufacturers' recommendations to change the default password." | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-26793.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet