VYPR

Fxa2000 Firmware

by Contec Co., Ltd.

CVEs (2)

  • CVE-2022-36159HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN…

  • CVE-2022-36158HigSep 26, 2022
    risk 0.52cvss 8.0epss 0.01

    Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).