MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.malighting.com/product-archive/product/grandma2-light-120112/ | product vendor advisory |
https://parzival.sh/posts/Pwning-a-Lighting-Console-in-a-Few-Minutes/ | third party advisory exploit |