CVE-2022-29730
Description
Hard-coded credentials in USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 allow full device compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Hard-coded credentials in USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 allow full device compromise.
Vulnerability
The USR IOT 4G LTE Industrial Cellular VPN Router running firmware version 1.0.36 contains hard-coded credentials for the highest privileged account (root). These credentials are embedded in the firmware and cannot be altered through normal device operation. [2]
Exploitation
An attacker with network access to the router can authenticate using the hard-coded credentials against services such as SSH or the web management interface. No additional authentication bypass is required. The credentials are static and widely accessible. [2]
Impact
Successful exploitation grants the attacker full administrative control over the router, enabling complete compromise of confidentiality (access to network traffic, configuration data), integrity (modify settings, install malicious firmware), and availability (disrupt device operation). [2]
Mitigation
As of the publication date (2022-05-27), no official firmware update addressing the hard-coded credentials has been released. Users should restrict network access to the device and monitor for vendor updates. The credentials cannot be changed via normal administration. [2]
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- USR IOT/4G LTE Industrial Cellular VPN Routerdescription
- Range: = 1.0.36
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- www.pusr.commitrex_refsource_MISC
- www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5705.phpmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.