Security
Headlines
HeadlinesLatestCVEs

Headline

TELSAT marKoni FM Transmitter 1.9.5 Backdoor Account

The transmitter has a hidden super administrative account ‘factory’ that has the hardcoded password ‘inokram25’ that allows full access to the web management interface configuration. The factory account is not visible in the users page of the application and the password cannot be changed through any normal operation of the device. The backdoor lies in the /js_files/LogIn_local.js script file. Attackers could exploit this vulnerability by logging in using the backdoor credentials for the web panel gaining also additional functionalities including: unit configuration, parameter modification, EEPROM overwrite, clearing DB, and factory log modification.

Zero Science Lab
#vulnerability#web#js#backdoor

Zero Science Lab: Latest News

Akuvox Smart Intercom/Doorphone Unauthenticated Stream Disclosure