Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-62252— Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login

Quick assessment

Affected
sipcapture homer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Homer 是一款开源的电信可观测性软件。在 11.0.283 版本之前,任何新部署的 Homer 系统若使用内部认证机制,其引导过程会自动创建一个名为 的管理员账户,密码为 (该密码以传统的 SHA-256 十六进制哈希形式存储)。系统未设置首次登录时强制修改密码的机制。因此,任何能够访问登录接口的攻击者均可立即获得完整的管理员权限。该漏洞已在版本 11.0.283 中修复。

CVSS 9.8 · Critical

Affected Version Matrix 1

VendorProduct Version RangeStatus
sipcapture homer < 11.0.283 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-62252

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login
Source: CVE Program / CVE List V5
Vulnerability Description
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的凭证
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sipcapture homer < 11.0.283 -

II. Public POCs for CVE-2026-62252

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-62252

请登录查看更多情报信息。

Other References for CVE-2026-62252 (4)

Same Patch Batch · sipcapture · 2026-10-07 · 3 CVEs total

CVE-2026-62253 9.8 CRITICAL Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
CVE-2026-62251 8.1 HIGH Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/qu

IV. Related Vulnerabilities

V. Comments for CVE-2026-62252

No comments yet


Leave a comment