VYPR
High severity7.5NVD Advisory· Published Jan 8, 2026· Updated Jun 17, 2026

CVE-2019-25279

CVE-2019-25279

Description

FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • iWT Ltd./FaceSentry Access Control Systemv5
    Range: 6.4.8 build 264
  • Range: =6.4.8
  • cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.2:*:*:*:*:*:*:*
    • cpe:2.3:o:iwt:facesentry_access_control_system_firmware:6.4.8:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.