漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lutron radioRA2、stanza和HomeworkQS 信任管理问题漏洞
Vulnerability Description
Lutron Electronics radioRA2等都是美国路创电子(Lutron Electronics)公司的一套照明控制系统。 Lutron radioRA2、stanza和HomeworkQS中存在信任管理问题漏洞,该漏洞源于用户无法禁用使用该协议的产品中默认的硬编码凭证。攻击者可借助TELNET会话利用该漏洞控制设备。
CVSS Information
N/A
Vulnerability Type
N/A