Severity

8.6

Vulnerability Type

Initialization of a Resource with an Insecure Default (CWE-1188)

Summary

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.