// For flags

CVE-2022-36159

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.

Se ha detectado que Contec FXA3200 versiones 1.13 y anteriores, contienen una contraseña hash embebida para root almacenada en el componente /etc/shadow. Como la fuerza de la contraseña es débil, puede ser descifrada en pocos minutos. Mediante esta credencial, un actor malicioso puede acceder a la interfaz del Wireless LAN Manager y abrir el puerto telnet para luego olfatear el tráfico o inyectar cualquier malware.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2022-07-18 CVE Reserved
  • 2022-09-26 CVE Published
  • 2025-03-30 EPSS Updated
  • 2025-05-21 CVE Updated
  • 2025-05-21 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-798: Use of Hard-coded Credentials
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Contec
Search vendor "Contec"
Fxa3000 Firmware
Search vendor "Contec" for product "Fxa3000 Firmware"
<= 1.13.00
Search vendor "Contec" for product "Fxa3000 Firmware" and version " <= 1.13.00"
-
Affected
in Contec
Search vendor "Contec"
Fxa3000
Search vendor "Contec" for product "Fxa3000"
--
Safe
Contec
Search vendor "Contec"
Fxa3020 Firmware
Search vendor "Contec" for product "Fxa3020 Firmware"
<= 1.13.00
Search vendor "Contec" for product "Fxa3020 Firmware" and version " <= 1.13.00"
-
Affected
in Contec
Search vendor "Contec"
Fxa3020
Search vendor "Contec" for product "Fxa3020"
--
Safe
Contec
Search vendor "Contec"
Fxa3200 Firmware
Search vendor "Contec" for product "Fxa3200 Firmware"
<= 1.13.00
Search vendor "Contec" for product "Fxa3200 Firmware" and version " <= 1.13.00"
-
Affected
in Contec
Search vendor "Contec"
Fxa3200
Search vendor "Contec" for product "Fxa3200"
--
Safe
Contec
Search vendor "Contec"
Fxa2000 Firmware
Search vendor "Contec" for product "Fxa2000 Firmware"
< 1.39.00
Search vendor "Contec" for product "Fxa2000 Firmware" and version " < 1.39.00"
-
Affected
in Contec
Search vendor "Contec"
Fxa2000
Search vendor "Contec" for product "Fxa2000"
--
Safe