radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default jstwo password, which allows remote attackers to gain access.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Thintune_extreme | Esesix | 2.4.38 (including) | 2.4.38 (including) |
| Thintune_l | Esesix | 2.4.38 (including) | 2.4.38 (including) |
| Thintune_m | Esesix | 2.4.38 (including) | 2.4.38 (including) |
| Thintune_mobile | Esesix | 2.4.38 (including) | 2.4.38 (including) |
| Thintune_s | Esesix | 2.4.38 (including) | 2.4.38 (including) |
| Thintune_xm | Esesix | 2.4.38 (including) | 2.4.38 (including) |
| Thintune_xs | Esesix | 2.4.38 (including) | 2.4.38 (including) |