CVE-2019-25279
EUVD-2026-161408.01.2026, 00:15
FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| iwt | facesentry_access_control_system_firmware | 5.7.0 |
| iwt | facesentry_access_control_system_firmware | 5.7.2 |
| iwt | facesentry_access_control_system_firmware | 6.4.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration