Description
There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during development and provides an additional attack surface.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
<=2.2.0
Credits
Stefan Viehböck | SEC Consult Vulnerability Lab
References
seclists.org/fulldisclosure/2025/May/23
r.sec-consult.com/echarge