Hard-coded TLS Certificate
Description
Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connection. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.00.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Hard-coded TLS certificate in Lanner IAC-AST2500A BMC firmware allows remote MitM attacks on HTTPS connections.
Vulnerability
The Lanner IAC-AST2500A BMC firmware version 1.00.0 uses a hard-coded TLS certificate by default. This allows an attacker to impersonate the device's HTTPS service if the certificate is known. The vulnerability is present in the standard firmware version 1.00.0 [2].
Exploitation
An unauthenticated remote attacker with network access to the device can perform a Man-in-the-Middle (MitM) attack. The attacker must be positioned on the network path between the user and the BMC, and the user must initiate an HTTPS connection. The attack complexity is high due to the need for precise timing and network position, and user interaction is required [2].
Impact
Successful exploitation allows the attacker to break the confidentiality and integrity of data exchanged via HTTPS. The attacker can intercept and modify traffic, potentially gaining access to sensitive information or injecting malicious content. The CVSS score is 5.8 (Medium) with scope change [2].
Mitigation
Updated BMC firmware versions that fix the issue are available from Lanner technical support. Users should contact Lanner to obtain the patched firmware. No workaround is mentioned in the references [2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2= 1.00.0+ 1 more
- (no CPE)range: = 1.00.0
- (no CPE)range: 1.00.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.