VYPR
Unrated severityNVD Advisory· Published Jan 7, 2026· Updated Jan 16, 2026

FaceSentry Access Control System 6.4.8 Cleartext Password Storage Vulnerability

CVE-2019-25279

Description

FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional authentication.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.