VYPR
Unrated severityNVD Advisory· Published Dec 15, 2004· Updated Apr 16, 2026

CVE-2004-1320

CVE-2004-1320

Description

Asante FM2008 firmware 1.06 contains a hardcoded backdoor account (superuser/asante) allowing remote attackers full CLI access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Asante FM2008 firmware 1.06 contains a hardcoded backdoor account (superuser/asante) allowing remote attackers full CLI access.

Vulnerability

The Asante FM2008 managed Ethernet switch running firmware version v01.06 includes a hardcoded backdoor account for the CLI interface (accessible via Telnet or serial port). The username is "superuser" and the password is "asante". This account is not documented in the user manual and cannot be changed through normal configuration commands. The backdoor credentials are separate from the user-configurable credentials used for the Web and terminal interfaces [1].

Exploitation

An attacker with network access to the switch's Telnet service (or physical access to the serial port) can connect and log in by entering "superuser" as the username and "asante" as the password. No additional authentication or user interaction is required. The CLI interface provides a "help" command listing available commands [1].

Impact

Successful exploitation grants the attacker full administrative access to the switch's CLI, enabling them to execute all available commands, including those that can alter device configuration, memory, or ports. This can lead to complete compromise of the switch's operation, including denial of service, unauthorized configuration changes, and potential network disruption [1].

Mitigation

No official patch or firmware update addressing this backdoor account has been identified in the available references. As the device is likely end-of-life, recommended mitigations include restricting Telnet and HTTP access to trusted networks via access control lists (ACLs), disabling unused management interfaces, and monitoring for unauthorized access attempts [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.