An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Obscuring a password with a trivial encoding does not protect the password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mbnet.mini_firmware | Mbconnectline | * | 2.3.1 (excluding) |