Unrated severityNVD Advisory· Published Jan 7, 2026· Updated Jan 16, 2026
FaceSentry Access Control System 6.4.8 Cleartext Password Storage Vulnerability
CVE-2019-25279
Description
FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional authentication.
Affected products
2- Range: =6.4.8
- iWT Ltd./FaceSentry Access Control Systemv5Range: 6.4.8 build 264
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/153501mitreexploit
- www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5529.phpmitrethird-party-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/163190mitrevdb-entry
News mentions
0No linked articles in our index yet.