The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as its password, which makes it easier for remote attackers to obtain access.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2008-02/0227.html - | |
References | () http://osvdb.org/42940 - | |
References | () http://secunia.com/advisories/28978 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/4536 - | |
References | () http://www.securenetwork.it/ricerca/advisory/download/SN-2008-01.txt - Exploit | |
References | () http://www.securityfocus.com/archive/1/488127/100/200/threaded - | |
References | () http://www.securityfocus.com/bid/27790 - | |
References | () http://www.vupen.com/english/advisories/2008/0583 - | |
References | () https://www.exploit-db.com/exploits/5113 - |
Information
Published : 2008-11-01 06:00
Updated : 2024-11-21 00:52
NVD link : CVE-2008-4874
Mitre link : CVE-2008-4874
CVE.ORG link : CVE-2008-4874
JSON object : View
Products Affected
philips_electronics
- voip841_dect_phone
CWE
CWE-255
Credentials Management Errors