Description
INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.
Problem types
Product status
505
515
1050
1050/G3
10100L
10100L/G3
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5546.php (Zero Science Lab Vulnerability Advisory)
www.exploit-db.com/exploits/47763 (Exploit Database Entry 47763)
packetstormsecurity.com/files/155618 (Packet Storm Security Exploit File)
exchange.xforce.ibmcloud.com/vulnerabilities/172838 (IBM X-Force Vulnerability Exchange Entry)
www.inim.biz/ (INIM Vendor Homepage)