Impact
Firmware version V300SP10260209 and earlier embed immutable administrative credentials that cannot be altered by users. Possession of these credentials grants complete control over the switch, enabling configuration changes, network traffic manipulation, and potential lateral movement. The vulnerability is a direct result of improper credential management (CWE‑798).
Affected Systems
Binardat Ltd.’s 10G08-0800GSM Network Switch is affected. All firmware releases up to and including V300SP10260209 possess the hard‑coded credential flaw.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity, while the EPSS score of < 1% suggests that exploitation events are currently rare but not impossible. The switch’s web‑based management interface is likely the attack surface; remote attackers who can reach the device’s management port may use the known credentials to gain full administrative control. The vulnerability is not listed in the CISA KEV catalog, but its high severity warrants caution.
OpenCVE Enrichment