← back
CVE-2025-46352

Consilium Safety CS5000 Fire Panel Use of Hard-coded Credentials

CVSS 9.3 CRITICALEPSS 0.7%CWE-798
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.3EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
29 May 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password cannot be altered, allowing anyone with knowledge of it to gain remote access to the panel. Such access could enable an attacker to operate the panel remotely, potentially putting the fire panel into a non-functional state and causing serious safety issues.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →