CVE-2007-2040Hard-coded Credentials in Cisco Wireless LAN Controller Software

CWE-264CWE-3995 documents5 sources
Severity
6.2MEDIUMNVD
EPSS
0.1%
top 74.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 1

Description

Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows attackers with physical access to perform arbitrary actions on the device, aka Bug ID CSCsg15192.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4g65-3hrc-pmpq: Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 32022-05-01
CVEList
CVE-2007-2040: Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 32007-04-16

💥Exploits & PoCs

1
Exploit-DB
OpenNewsletter 2.5 - 'Compose.php' Cross-Site Scripting2007-12-06

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points2007-04-12
CVE-2007-2040 — Hard-coded Credentials in Cisco | cvebase