Inim Electronics SmartLiving 505
cpe:2.3:o:inim:smartliving_505_firmware:*:*:*:*:*:*:*, +1 more
- <= 6.x
A vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI versions 6.x and prior, due to hard-coded credentials embedded in the Linux distribution image. These credentials, which provide Telnet, SSH, and FTP access, cannot be altered through normal device operations. As a result, attackers can exploit this vulnerability to gain unauthorized system access across various SmartLiving device models.
Exploitation of this vulnerability allows for unauthorized system access via Telnet, SSH, and FTP. Additionally, according to the vendor, this vulnerability could lead to a denial-of-service.
The vulnerability can be reproduced by accessing the device via Telnet, SSH, or FTP using the hard-coded credentials. Once logged in, the credentials can be verified by checking the password hashes, which reveal the root password as 'pass'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.