CVE-2024-44815
10.09.2024, 16:15
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.Enginsight
Vendor | Product | Version |
---|---|---|
hathway | skyworth_cm5100-511_firmware | 4.1.1.24 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
- CWE-256 - Plaintext Storage of a PasswordStoring a password in plaintext may result in a system compromise.