ETIC Telecom Remote Access Server Cleartext Credentials Exposure Vulnerability

Vulnerability

A vulnerability exists in all versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0, where cleartext credentials are exposed in the web portal. This allows an attacker to access the ETIC RAS web portal, view hidden HTML code, and connect to the ETIC RAS SSH server, potentially enabling actions on the device.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the ETIC RAS SSH server, allowing an attacker to perform actions on the affected device.

Remediation

Users are advised to update to ETIC Telecom Remote Access Server version 4.5.0 or later. For versions prior to 4.5.0, ETIC Telecom recommends ensuring that the administration web page is accessible only through the LAN side over HTTPS and is protected with authentication.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
7.6
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.