CVE-2017-12574: Critical severity PLANEX Cs-w50hd Firmware vulnerability
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpasswd" during booting process, which allows attackers to gain unauthorized access and control the device completely; the account can't be modified or deleted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12574?
CVE-2017-12574 is classified as a high severity vulnerability due to the presence of hardcoded credentials allowing complete device control.
How do I fix CVE-2017-12574?
To mitigate CVE-2017-12574, update the firmware of the PLANEX CS-W50HD device to version 030720 or later.
What devices are affected by CVE-2017-12574?
CVE-2017-12574 affects PLANEX CS-W50HD devices running firmware versions prior to 030720.
Can CVE-2017-12574 be exploited remotely?
Yes, CVE-2017-12574 can be exploited remotely by attackers to gain unauthorized access to the device due to hardcoded credentials.
What happens if I don't address CVE-2017-12574?
If CVE-2017-12574 is not addressed, attackers can exploit the vulnerability to take full control of the affected device.