CVE-2022-29730
USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.
Published:May 27, 2022
Last Modified:Nov 21, 2024
EPS:May 27, 2022
EPSS Score:0.00643
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Usr
Product
Usr-g800v2
Usr
Usr-g800v2
Vendor
Usr
Product
Usr-g800v2 Firmware
Usr
Usr-g800v2 Firmware
Vendor
Usr
Product
Usr-g806
Usr
Usr-g806
Vendor
Usr
Product
Usr-g806 Firmware
Usr
Usr-g806 Firmware
Vendor
Usr
Product
Usr-g807
Usr
Usr-g807
Vendor
Usr
Product
Usr-g807 Firmware
Usr
Usr-g807 Firmware
Vendor
Usr
Product
Usr-g808
Usr
Usr-g808
Vendor
Usr
Product
Usr-g808 Firmware
Usr
Usr-g808 Firmware
Vendor
Usr
Product
Usr-lg220-l
Usr
Usr-lg220-l
Vendor
Usr
Product
Usr-lg220-l Firmware
Usr
Usr-lg220-l Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
