CVE-2018-5399: The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running and is configured with a hard-coded credentials

Published Oct 8, 2018
·
Updated

The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. The Dropbear server is configured with a hard-coded user name and password combination of root / amroot. The server is configured to use password only authentication not cryptographic keys, however the firmware image contains an RSA host-key for the server. An attacker can exploit this vulnerability to gain root access to the Angstrom Linux operating system and modify any binaries or configuration files in the firmware. Affected releases are Auto-Maskin DCU-210E RP-210E: Versions prior to 3.7 on ARMv7.

Affected Software

4 affected components
Auto-Maskin Dcu-210e Firmware<3.7
Auto-Maskin DCU-210E
Auto-Maskin Rp-210e Firmware<3.7
Auto-Maskin RP-210E

Remediation

Information

End-users should log-in via the SSH server and remove it as a service, or change the hard-coded password to SP 800-63B standards.

Event History

Oct 8, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2018-5399?

CVE-2018-5399 is considered a critical vulnerability due to the presence of hard-coded credentials in the Dropbear SSH server.

2

How do I fix CVE-2018-5399?

To mitigate CVE-2018-5399, users should upgrade the Auto-Maskin DCU 210E firmware to a version that does not include this vulnerability.

3

What products are impacted by CVE-2018-5399?

CVE-2018-5399 affects the Auto-Maskin DCU 210E and RP 210E firmware versions prior to 3.7.

4

Is it safe to use the Auto-Maskin DCU 210E with CVE-2018-5399?

Using the Auto-Maskin DCU 210E with CVE-2018-5399 poses significant security risks due to the exposure of hard-coded credentials.

5

What is the attack vector for CVE-2018-5399?

The attack vector for CVE-2018-5399 is remote, as it allows unauthorized access via the SSH server listening on Port 22.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203