Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml
Vulnerability Description
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing static plaintext credentials in the page source. Unauthenticated attackers with network access can recover administrative credentials directly from the client-side validate() function to obtain full administrative access to the device.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
Taiko AG1000-01A SMS Alert Gateway 信任管理问题漏洞
Vulnerability Description
Taiko AG1000-01A SMS Alert Gateway是新加坡Taiko公司的一款支持短信告警通知与远程事件消息转发的工业通信网关设备。 Taiko AG1000-01A SMS Alert Gateway Rev 7.3版本和Rev 8版本存在信任管理问题漏洞,该漏洞源于嵌入式Web配置界面中存在硬编码凭据,可能导致未经身份验证的攻击者恢复管理凭据并获得完全管理访问权限。
CVSS Information
N/A
Vulnerability Type
N/A