VYPR
Unrated severityNVD Advisory· Published Mar 21, 2022· Updated Aug 4, 2024

CVE-2021-45877

CVE-2021-45877

Description

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • GARO/Wallbox GLB/GTB/GTCdescription
  • GARO/Wallboxllm-create

Patches

Vulnerability mechanics

Root cause

"Hardcoded credentials in /etc/tomcat8/tomcat-user.xml allow unauthorized access to the Tomcat Manager."

Attack vector

An attacker can use the hardcoded credential found in `/etc/tomcat8/tomcat-user.xml` to authenticate to the Tomcat Manager web interface on port 8000 [ref_id=1]. No prior authentication or special network position is required beyond network access to the device's port 8000. Once authenticated, the attacker gains full administrative control over the Tomcat server, enabling them to deploy, start, stop, or remove web applications [ref_id=1].

Affected code

The hardcoded credential is stored in the file `/etc/tomcat8/tomcat-user.xml` on the GARO Wallbox device [ref_id=1]. This file contains the Tomcat user configuration, and the credential cannot be modified or deleted by a normal user [ref_id=1].

What the fix does

The advisory states that the vendor (GARO) did not respond to multiple contact attempts, and no fixed version was confirmed at the time of disclosure [ref_id=1]. The recommended remediation is to remove or change the hardcoded credential in `/etc/tomcat8/tomcat-user.xml` and restrict access to the Tomcat Manager port (8000) via network controls. No official patch has been published by the vendor [ref_id=1].

Preconditions

  • networkNetwork access to the GARO Wallbox device on TCP port 8000
  • inputKnowledge of the hardcoded credential stored in /etc/tomcat8/tomcat-user.xml

Generated on May 25, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

1

News mentions

0

No linked articles in our index yet.