EDB-ID: 50407 CVE: N/A Author: LiquidWorm Type: Remote Platform: Hardware Date: 2021-10-13 Vulnerable App: Cypress Solutions CTM-200/CTM-ONE Vulnerability Details Vulnerability: Hard-coded Credentials Remote Root (Telnet/SSH) Description: - The CTM-200 and CTM-ONE are vulnerable to hard-coded credentials within their Linux distribution image. This can lead to exposure of resources or functionality to unintended actors. - Attackers can gain sensitive information and execute arbitrary code. Affected Systems ```bash CTM-200 /var/config/passwd: root:$1$5SSS5yR6V$Lo9Qc3rp/7UCU8fRq5ec0:0:0:root:/root:/bin/sh admin:$1$5SSS5yR6V$Lo9Qc3rp/7UCU8fRq5ec0:0:0:root:/root:/bin/sh nobody::65534:65534:nobody:/var/bin/false daemon::65534:65534:daemon:/var/bin/false CTM-ONE /etc/shadow: admin:$6$S2Co5pXS.Tza5AF55KX2XKQrjENNkqQFRBRB2aiEujayHE5Ese7tdcxkXf1EPQqDV3/d2u3D/OHlgnNU8f9Pn5.g061vx/:17689:0:99999:7::: root:$S5HHLzQf$GlW2NBioce/kMpc2JGMHbyDuuiJJy/zYhKQjsi4JSx8cur0FYhSDmg5TiTXaehqu/d6ZtXNZtEC2hLJLrLC/:17689:0:99999:7::: daemon:*:16009:0:99999:7:::