The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-02T00:56:58.148Z
Reserved: 2024-03-08T05:25:54.146Z
Link: CVE-2024-28744
Updated: 2024-07-31T18:16:40.015Z
Status : Awaiting Analysis
Published: 2024-04-08T01:15:56.660
Modified: 2024-11-21T09:06:52.213
Link: CVE-2024-28744
No data.
OpenCVE Enrichment
No data.
Weaknesses