The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PIN
Description
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PIN Impact: An attacker once authenticated can change configurations, upload new configuration files, and upload executable code via file upload for firmware updates. Requires access to the network. Affected releases are Auto-Maskin DCU-210E, RP-210E, and the Marine Pro Observer Android App. Versions prior to 3.7 on ARMv7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit the administrator PIN in cleartext via the embedded webserver, allowing network-adjacent attackers to authenticate and gain full control.
Vulnerability
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App (versions prior to 3.7 on ARMv7) contain a cleartext transmission vulnerability (CWE-319) in the embedded web server [1][2]. The administrator PIN is transmitted over HTTP without encryption, enabling unauthorized actors to capture the credential by sniffing network traffic [1][2].
Exploitation
An attacker with network access to the affected device can monitor network traffic to capture the plaintext administrator PIN [1][2]. No authentication is required beforehand, and the attack requires only low skill [1]. Once the PIN is obtained, the attacker can authenticate to the web server and perform privileged actions [1].
Impact
Successful exploitation allows an authenticated attacker to change configurations, upload new configuration files, and upload executable code via the file upload mechanism used for firmware updates [1]. This can lead to full compromise of the device, including root access to the underlying operating system and read/write access to system files [1].
Mitigation
As of the publication date, the vendor had not released a firmware update addressing this vulnerability; CERT/CC was unaware of a solution [2]. Affected users should ensure these devices are accessible only via private, carefully secured networks [2]. CISA advisory ICSA-20-051-04 recommends following defense-in-depth practices but does not announce a patch [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5- Range: <3.7
- Range: <3.7
- Auto-Maskin/DCU-210Ev5Range: 3.7
- Auto-Maskin/RP-210Ev5Range: 3.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.kb.cert.org/vuls/id/176301mitrethird-party-advisoryx_refsource_CERT-VN
- www.us-cert.gov/ics/advisories/icsa-20-051-04mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.