Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://gist.github.com/Nwqda/0db1fc6cfa39d7f0592d44e18c40146e | broken link |
https://www.seiko-sol.co.jp/products/skybridge/lineup/mb-a200/ | product vendor advisory |