Description
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interface and HTTP responses, allowing recovery of valid credentials.
Problem types
CWE-201 Insertion of Sensitive Information Into Sent Data
CWE-317 Cleartext Storage of Sensitive Information in GUI
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
www.binardat.com/...al-fanless-fiber-binardat-network-switch
www.vulncheck.com/...work-switch-plaintext-password-exposure