See how victure compares to other vendors in security performance
Victure RX1800 ENV1.0.0r12110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.
An issue in Victure RX1800 ENV1.0.0r12110933 allows physically proximate attackers to execute arbitrary code or gain root access.
Incorrect access control in Victure RX1800 ENV1.0.0r12110933 allows attackers to enable SSH and Telnet services without authentication.
Victure RX1800 ENV1.0.0r12110933 was discovered to contain a command injection vulnerability.
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabledtelnet.dat on the Micro SD card.
Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
An issue was discovered in Victure RX1800 WiFi 6 Router (software ENV1.0.0r12110933, hardware 1.0) devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default Wi-Fi PSK value via the last 4 octets of the BSSID.
An issue was discovered in Victure RX1800 WiFi 6 Router (software ENV1.0.0r12110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dualfrequnapple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.
An issue was discovered in Victure RX1800 WiFi 6 Router (software ENV1.0.0r12110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints are vulnerable to command injection. Attackers can exploit this by sending crafted payloads through parameters intended for the ping utility, enabling arbitrary command execution with root-level permissions on the device.
An issue was discovered in Victure RX1800 WiFi 6 Router (software ENV1.0.0r12110933, hardware 1.0) devices. The TELNET service is enabled by default and exposed over the LAN. The root account is accessible without a password, allowing attackers to achieve full control over the router remotely without any authentication.
An issue was discovered on Victure RX1800 WiFi 6 Router (software ENV1.0.0r12110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. The allows attackers to execute arbitrary commands with root-level permissions. Device setup does not require this password to be changed during setup in order to utilize the device. (However, the TELNET password is dictated by the current GUI password.)