Description
Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.
Problem types
Product status
Credits
Ismail Tasdelen
References
www.exploit-db.com/exploits/47823 (ExploitDB-47823)
web.archive.org/...90724160628/https://www.heatmiser.com/en/ (Archived Heatmiser Official Website)
www.zoneregeling.nl/heatmiser/netmonitor-handleiding.pdf (Netmonitor User Manual)
www.vulncheck.com/...tmiser-netmonitor-hardcoded-credentials (VulnCheck Advisory: Heatmiser Netmonitor 3.03 - Hardcoded Credentials)