Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.l9group.com/advisories/hard-coded-default-root-credentials-for-all-ecobee3-lite-devices | third party advisory exploit |