Description
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Because the key is static and exposed, an attacker can decrypt protected values and defeat confidentiality protections.
Problem types
CWE-321 Use of Hard-coded Cryptographic Key
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
www.binardat.com/...al-fanless-fiber-binardat-network-switch
www.vulncheck.com/...rk-switch-hard-coded-rc4-encryption-key