Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://blog.securityevaluators.com/remotely-exploiting-iot-pet-feeders-21013562aea3 | third party advisory exploit |