CVE-2026-24455

The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) La interfaz web integrada del dispositivo no es compatible con HTTPS/TLS para autenticación y utiliza Autenticación Básica HTTP. El tráfico está codificado pero no cifrado, exponiendo las credenciales de usuario a la interceptación pasiva por atacantes en la misma red.

20 Feb 2026, 17:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 17:25

Updated : 2026-04-15 00:35


NVD link : CVE-2026-24455

Mitre link : CVE-2026-24455

CVE.ORG link : CVE-2026-24455


JSON object : View

Products Affected

No product.

CWE
CWE-319

Cleartext Transmission of Sensitive Information