ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://csirt.divd.nl/CVE-2025-36747/ |
|
History
Sat, 13 Dec 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced. | |
| Title | Hardcoded FTP Credentials within the firmware | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2025-12-13T08:16:25.804Z
Reserved: 2025-04-15T21:54:36.813Z
Link: CVE-2025-36747
No data.
Status : Received
Published: 2025-12-13T16:16:53.710
Modified: 2025-12-13T16:16:53.710
Link: CVE-2025-36747
No data.
OpenCVE Enrichment
No data.
Weaknesses