CVE-2024-45275: MB connect line/Helmholz: Hardcoded user accounts with hard-coded passwords
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45275?
CVE-2024-45275 is considered a high severity vulnerability due to the presence of hardcoded user accounts that allow remote attackers full control of the affected devices.
How do I fix CVE-2024-45275?
To fix CVE-2024-45275, update the firmware of the affected devices to a version that does not contain the hardcoded credentials.
Which devices are affected by CVE-2024-45275?
CVE-2024-45275 affects devices running the Mbconnectline Mbnet.mini firmware versions up to 2.3.1 and Helmholz Rex 100 firmware versions up to 2.3.1.
Can CVE-2024-45275 be exploited remotely?
Yes, CVE-2024-45275 can be exploited remotely by unauthenticated attackers due to hardcoded accounts.
What are the implications of CVE-2024-45275 for device security?
The implications of CVE-2024-45275 for device security include unauthorized access, potential data breaches, and loss of control over the affected devices.