The CS5000 Fire Panel is vulnerable due to a default account that exists
on the panel. Even though it is possible to change this by SSHing into
the device, it has remained unchanged on every installed system
observed. This account is not root but holds high-level permissions that
could severely impact the device's operation if exploited.
References
Configurations
No configuration.
History
30 May 2025, 16:31
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
30 May 2025, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-30 00:15
Updated : 2025-05-30 16:31
NVD link : CVE-2025-41438
Mitre link : CVE-2025-41438
CVE.ORG link : CVE-2025-41438
JSON object : View
Products Affected
No product.
CWE
CWE-1188
Insecure Default Initialization of Resource