High severity7.5NVD Advisory· Published Jan 8, 2026· Updated Jun 17, 2026
CVE-2019-25279
CVE-2019-25279
Description
FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- iWT Ltd./FaceSentry Access Control Systemv5Range: 6.4.8 build 264
- Range: =6.4.8
cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.2:*:*:*:*:*:*:*
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:6.4.8:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/153501nvdExploitThird Party Advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5529.phpnvdExploitThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/163190nvdThird Party Advisory
News mentions
0No linked articles in our index yet.