Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22).
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://github.com/goldshellminer/firmware | third party advisory |
https://jamesachambers.com/cryptocurrency-asic-miners-security-and-hacking-audit/ | exploit third party advisory mitigation |