CVE-2021-46247

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:cmax6000_firmware:1.02.00:*:*:*:*:*:*:*
cpe:2.3:h:asus:cmax6000:-:*:*:*:*:*:*:*

History

25 Feb 2022, 18:00

Type Values Removed Values Added
CWE CWE-798
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (MISC) https://drive.google.com/drive/folders/1lSaxWKiNKRkeZxQanEMpt906aUgDGUk_?usp=sharing - (MISC) https://drive.google.com/drive/folders/1lSaxWKiNKRkeZxQanEMpt906aUgDGUk_?usp=sharing - Exploit, Third Party Advisory
CPE cpe:2.3:h:asus:cmax6000:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:cmax6000_firmware:1.02.00:*:*:*:*:*:*:*

17 Feb 2022, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-17 19:15

Updated : 2024-02-04 22:29


NVD link : CVE-2021-46247

Mitre link : CVE-2021-46247

CVE.ORG link : CVE-2021-46247


JSON object : View

Products Affected

asus

  • cmax6000_firmware
  • cmax6000
CWE
CWE-798

Use of Hard-coded Credentials