Impact
The vulnerability resides in the web configuration interface where authentication is implemented entirely in client‑side JavaScript in login.zhtml. The JavaScript code contains static plaintext credentials, a classic hard‑coded credential flaw (CWE‑798). An unauthenticated attacker who can reach the web interface can extract these credentials from the page source, enabling full administrative access to the device without needing prior authentication.
Affected Systems
Taiko Network Communications Pte Ltd’s AG1000‑01A SMS Alert Gateway, specifically Rev 7.3 and Rev 8 released versions.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. An attacker only needs network access to the web interface and can exploit the flaw trivially by inspecting the page source; no special privileges or complex conditions are required, making the risk high for any device exposed to potentially untrusted networks.
OpenCVE Enrichment