← back
CVE-2026-35075criticalCWE-1393

Hardcoded default Password for Service Account

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.3epss 0.5%
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
In short

A default password is embedded in the firmware of affected devices, allowing anyone who downloads the firmware to discover it and gain full control of the system without needing to log in first.

Technical detail

An attacker can extract the hardcoded service account credentials from publicly available or accessible firmware images, enabling unauthenticated remote access with full privileges. Pre-condition: ability to obtain the firmware; impact: complete device compromise and lateral movement within the network.

Summary generated and translated by AI from the official description.
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N