Impact
The vulnerability stems from a hardcoded master verification code in Siam Ordering server version 1.0.0, allowing remote attackers to authenticate themselves as any existing user without supplying valid credentials. This flaw grants full account impersonation and access to merchant or administrator functions, thereby compromising confidentiality and integrity of both user and system data. It is a classic example of improper use of hard‑coded credentials that undermines the authentication layer.
Affected Systems
Siam Ordering server, version 1.0.0. No vendor information is listed, but the product name and version identify the affected system.
Risk and Exploitability
The threat can be executed remotely over the network with no authentication required to gain access. The EPSS score is less than 1%, indicating a very low but non‑zero exploitation probability. The CVSS score of 8.1 signals a high severity vulnerability, and the absence of an exploitation barrier combined with the ability to impersonate any user rank this issue as high risk. The vulnerability is not listed in the CISA KEV catalog, but the potential for widespread abuse remains if the hard‑coded credentials are not removed or protected.
OpenCVE Enrichment