CVE Vulnerabilities

CVE-2024-44815

Insufficiently Protected Credentials

Published: Sep 10, 2024 | Modified: Sep 25, 2024
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Skyworth_cm5100-511_firmware Hathway 4.1.1.24 (including) 4.1.1.24 (including)

Potential Mitigations

References