Zettler TCP/IP Gateway Default Credentials Vulnerability
Vulnerability
A vulnerability allowing the use of default credentials has been identified in the Zettler 130.8005 TCP/IP Gateway, specifically in devices running firmware version 12h. The gateway's FTP server is accessible with default admin credentials that are easy to guess. This vulnerability could allow a remote attacker to access the FTP server and modify resources available through the service, such as configuration files containing password hashes or network settings.
Impact
Exploitation of this vulnerability could lead to unauthorized access to the FTP server, allowing attackers to change configuration files, access password hashes, or modify network settings.
Remediation
It is recommended to move the device to a management VLAN where only authorized clients can interact with it.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
