An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
The product contains hard-coded credentials, such as a password or cryptographic key.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1431 | third party advisory exploit |