Description
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.
Problem types
Product status
6.4.8 build 264
5.7.2 build 568
5.7.0 build 539
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5526.php
www.exploit-db.com/exploits/47067 (ExploitDB-47067)
www.iwt.com.hk (Vendor Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5526.php (Zero Science Lab Disclosure (ZSL-2019-5526))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.