CVE-2018-17919
10.10.2018, 15:29
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.Enginsight
Vendor | Product | Version |
---|---|---|
xiongmaitech | xmeye_p2p_cloud_server | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-912 - Hidden FunctionalityThe software contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the software's users or administrators.
- CWE-798 - Use of Hard-coded CredentialsThe software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.