ALLNET ALL-RUT22GW Hard-Coded Credential Vulnerability

Vulnerability

A vulnerability exists in the ALLNET ALL-RUT22GW 4G LTE cellular router, specifically in version 3.3.8. The issue arises from hard-coded credentials embedded within the libicos.so library, which grant unauthorized access to the device's web management interface. This access could allow attackers to alter device settings and gain full control over the router.

Impact

Exploitation of this vulnerability provides unauthorized users with access to the router's web management panel, allowing them to change settings and potentially take complete control of the device.

Reproduction

The vulnerability can be reproduced by logging into the router's management panel using the hard-coded credentials. The username 'iwu@fbt&ND' and the password 'wut@uty&2210' can be used to gain 'system' access, the highest level of privilege on the device.

Added: Dec 4, 2025, 8:25 PM
Updated: Dec 4, 2025, 8:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.