VYPR
Unrated severityNVD Advisory· Published Nov 10, 2021· Updated Aug 4, 2024

CVE-2021-40520

CVE-2021-40520

Description

Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Airangel HSMX Gateway devices through version 5.2.04 use default or weak SSH credentials, allowing remote attackers to gain root access.

Vulnerability

Airangel HSMX Gateway devices running firmware versions through 5.2.04 ship with default or weak SSH credentials that cannot be changed through the administrative interface [1]. The SSH service is enabled by default and exposes a command-line interface to the underlying operating system.

Exploitation

An attacker with network access to the management interface (typically port 22/TCP) can attempt to authenticate using known default credentials or perform a brute-force attack. No prior authentication or user interaction is required. The weak credential policy makes it feasible to guess or enumerate valid login pairs.

Impact

Successful authentication via SSH grants the attacker a root shell on the device, resulting in full system compromise. An attacker can read sensitive configuration files, modify device settings, intercept or redirect network traffic, and use the gateway as a pivot point into the internal network.

Mitigation

Airangel has not released a firmware update that addresses this weakness as of the publication date [1]. Users should restrict SSH access to trusted IP addresses via firewall rules, use strong unique passwords if the device allows credential changes, and monitor device logs for unauthorized SSH attempts. If possible, disable SSH on the gateway when not required.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.