An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Obscuring a password with a trivial encoding does not protect the password.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Mbnet.mini_firmware | Mbconnectline | * | 2.3.1 (excluding) |