CVE-2021-47744: Cypress Solutions CTM-200/CTM-ONE 1.3.6 Hard-coded Credentials Remote Root

Published Dec 31, 2025
·
Updated

Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on affected devices.

Affected Software

1 affected component
Cypress Solutions CTM-200/CTM-ONE

Event History

Dec 31, 2025
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2021-47744?

CVE-2021-47744 is considered a high severity vulnerability due to its potential for remote root access via hard-coded credentials.

2

How do I fix CVE-2021-47744?

To remediate CVE-2021-47744, update the device firmware to a version that eliminates the hard-coded 'Chameleon' password.

3

What are the consequences of exploiting CVE-2021-47744?

Exploiting CVE-2021-47744 allows an attacker to gain remote root access, compromising the entire system and its data.

4

Which devices are affected by CVE-2021-47744?

CVE-2021-47744 affects Cypress Solutions CTM-200 and CTM-ONE devices running version 1.3.6.

5

How can I identify if CVE-2021-47744 is present on my device?

To identify CVE-2021-47744, check if your device is running the vulnerable version 1.3.6 and verify if it has the hard-coded 'Chameleon' password.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203