CVE-2025-36747: Hardcoded FTP Credentials within the firmware
ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36747?
CVE-2025-36747 is classified as a high severity vulnerability due to the potential for unauthorized file manipulation.
How do I fix CVE-2025-36747?
To fix CVE-2025-36747, update the firmware of ShineLan-X to a version that does not include hardcoded FTP credentials.
What is the vulnerability in CVE-2025-36747?
CVE-2025-36747 allows attackers to exploit hardcoded FTP credentials to establish insecure connections and replace legitimate files.
Which devices are affected by CVE-2025-36747?
CVE-2025-36747 specifically affects the ShineLan-X firmware.
Can CVE-2025-36747 lead to data loss?
Yes, CVE-2025-36747 can lead to data loss as attackers can replace legitimate files with malicious ones.