Critical severity9.8NVD Advisory· Published Dec 24, 2025· Updated Jun 17, 2026
CVE-2019-25241
CVE-2019-25241
Description
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.2:*:*:*:*:*:*:*
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:6.4.8:*:*:*:*:*:*:*
- Range: =6.4.8
- iWT Ltd./FaceSentry Access Control Systemv5Range: 6.4.8 build 264
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/47067nvdExploitThird Party AdvisoryVDB Entry
- www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5526.phpnvdExploitThird Party Advisory
- www.iwt.com.hknvdProduct
News mentions
0No linked articles in our index yet.