VYPR
Unrated severityNVD Advisory· Published Nov 10, 2021· Updated Aug 4, 2024

CVE-2021-40519

CVE-2021-40519

Description

Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Airangel HSMX Gateway devices up to 5.2.04 ship with hard-coded database credentials, allowing remote attackers to access the backend database.

Vulnerability

The Airangel HSMX Gateway, versions through 5.2.04, contains hard-coded database credentials [1]. The credentials are embedded in the device firmware, enabling anyone with network access to the database port to authenticate without needing legitimate credentials. The affected product is the HSMX Gateway, which runs Airangel's ElevenOS platform for Wi-Fi authentication and performance management [1]. All firmware versions up to and including 5.2.04 are vulnerable.

Exploitation

An attacker with network access to the HSMX Gateway's database service (typically MySQL or MariaDB on the default port 3306) can attempt to connect using the well-known hard-coded credentials. No authentication bypass, user interaction, or elevated privileges are required beyond the ability to reach the database port. The attacker can connect directly using a database client and the hard-coded username and password.

Impact

Successful exploitation gives the attacker full read and write access to the backend database. This can lead to disclosure of sensitive information stored in the database, such as user credentials, Wi-Fi configuration data, guest lists, and possibly administrative passwords. The attacker may also modify or delete data, potentially causing denial of service or privilege escalation within the management interface.

Mitigation

Airangel has not publicly disclosed a fixed version for the HSMX Gateway as of the publication date [1]. Users should restrict network access to the database port (3306) using firewall rules to only trusted management hosts. If possible, change the default database credentials via the product's administrative interface or configuration files. Check the vendor's website or support portal for firmware updates that address this issue [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.