CVE-2023-49256
HIGHDescription
It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.
Is your site exposed to CVE-2023-49256?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hongdian | h8951-4g-esp_firmware |
| hongdian | h8951-4g-esp |
References
Frequently Asked Questions
What is CVE-2023-49256? +
How severe is CVE-2023-49256? +
What products are affected by CVE-2023-49256? +
How do I check if I'm vulnerable to CVE-2023-49256? +
Related Vulnerabilities
This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An …
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link …
: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue …
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused …
The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 …
A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and …