VYPR
Unrated severityNVD Advisory· Published Oct 8, 2018· Updated Sep 16, 2024

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PIN

CVE-2018-5402

Description

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PIN Impact: An attacker once authenticated can change configurations, upload new configuration files, and upload executable code via file upload for firmware updates. Requires access to the network. Affected releases are Auto-Maskin DCU-210E, RP-210E, and the Marine Pro Observer Android App. Versions prior to 3.7 on ARMv7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit the administrator PIN in cleartext via the embedded webserver, allowing network-adjacent attackers to authenticate and gain full control.

Vulnerability

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App (versions prior to 3.7 on ARMv7) contain a cleartext transmission vulnerability (CWE-319) in the embedded web server [1][2]. The administrator PIN is transmitted over HTTP without encryption, enabling unauthorized actors to capture the credential by sniffing network traffic [1][2].

Exploitation

An attacker with network access to the affected device can monitor network traffic to capture the plaintext administrator PIN [1][2]. No authentication is required beforehand, and the attack requires only low skill [1]. Once the PIN is obtained, the attacker can authenticate to the web server and perform privileged actions [1].

Impact

Successful exploitation allows an authenticated attacker to change configurations, upload new configuration files, and upload executable code via the file upload mechanism used for firmware updates [1]. This can lead to full compromise of the device, including root access to the underlying operating system and read/write access to system files [1].

Mitigation

As of the publication date, the vendor had not released a firmware update addressing this vulnerability; CERT/CC was unaware of a solution [2]. Affected users should ensure these devices are accessible only via private, carefully secured networks [2]. CISA advisory ICSA-20-051-04 recommends following defense-in-depth practices but does not announce a patch [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.