Use of Hard-coded Credentials in UWP3.0 allows SuperUser authentication bypass in Car Park Server.
Description
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Hard-coded credentials in Carlo Gavazzi UWP 3.0 and CPY Car Park Server 2.8.3 let remote unauthenticated attackers gain SuperUser access.
Vulnerability
Carlo Gavazzi UWP 3.0 (multiple versions) and CPY Car Park Server version 2.8.3 ship with hard-coded credentials embedded in the device firmware [1]. These credentials are not altered during initial setup, allowing a remote, unauthenticated attacker to authenticate as SuperUser via SSH, HTTPS, or the embedded web interface without any additional configuration requirements [1].
Exploitation
An attacker with network connectivity to the device can simply supply the hard-coded username and password (undisclosed in the advisory) to gain administrative access [1]. No authentication, user interaction, or prior knowledge is required beyond the device IP address. The attacker can leverage standard remote management protocols or the web interface to authenticate [1].
Impact
Successful exploitation grants the attacker SuperUser privileges on the affected device [1]. This yields full control over the controller or server, including ability to read/modify configuration, firmware, and all operational data, potentially impacting availability, integrity, and confidentiality of the connected industrial control system [1].
Mitigation
Carlo Gavazzi has released updated firmware for UWP 3.0 and CPY Car Park Server that removes the hard-coded credentials [1]. Users should update to the latest version as specified in VDE-2022-029 [1]. No effective workaround other than restricting network access via firewall rules is available for unpatched devices [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
6=2.8.3+ 1 more
- (no CPE)range: =2.8.3
- (no CPE)range: 2
- Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controllerv5Range: 8
- Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controller – EDP versionv5Range: 8
- Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controller – Security Enhancedv5Range: 8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- cert.vde.com/en/advisories/VDE-2022-029/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.