Impact
The vulnerability arises from a hardcoded master verification code in Siam Ordering server 1.0.0, enabling remote attackers to authenticate as any user without providing valid credentials. This flaw permits full account impersonation and access to merchant or administrator functions, compromising confidentiality and integrity of user and system data. The weakness is a classic example of improper use of hard‑coded credentials, which undermines the authentication layer.
Affected Systems
Siam Ordering server, version 1.0.0. No vendor information is listed, but the product name and version identify the affected system.
Risk and Exploitability
The threat can be executed remotely over the network, with no authentication required to gain access. While the EPSS score is not available, the lack of an exploitation barrier and the ability to impersonate any user rank this issue as high risk. The vulnerability is not currently listed in the CISA KEV catalog, but the potential for widespread abuse remains if the hard-coded credentials are not removed or protected.
OpenCVE Enrichment