Local password disclosure via UART logs
Published Sep 14, 2023 · Updated Sep 25, 2024
Insufficiently protected credentials in Sichuan Tianyi Comheart Telecom Tianyi Home Gateway TEWA-700G allow local attackers to read default password via UART logs. During console log output, firmware prints the gateway's default password in clear text instead of protecting or redacting it. An attacker needs physical access to disassemble the appliance and connect to its TTL UART interface; exposed credentials can enable authenticated administration and disclosure of sensitive information.
Summary
What happened
Insufficiently protected credentials in Sichuan Tianyi Comheart Telecom Tianyi Home Gateway TEWA-700G allow local attackers to read default password via UART logs. During console log output, firmware prints the gateway's default password in clear text instead of protecting or redacting it. An attacker needs physical access to disassemble the appliance and connect to its TTL UART interface; exposed credentials can enable authenticated administration and disclosure of sensitive information.
The record
- CVE
- CVE-2023-41010
- Published
- Sep 14, 2023
- Updated
- Sep 25, 2024
- Vendor
- Sichuan Tianyi Comheart Telecom Co., Ltd.
- Product
- China Telecom Tianyi Home Gateway
- Classifications
- CWE-522, T1552.001
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Sep 14, 2023CVE publishedPublication date reported by the CVE source.
- Sep 25, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=v.tewa-700g
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- TEWA-700G UART default-password disclosure proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo