CVE-2022-3203: ORing net IAP-420(+) Hidden Functionality
On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative shell. These credentials are reset to defaults with every reboot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3203?
CVE-2022-3203 is considered a high severity vulnerability due to the risk of unauthorized access through hardcoded administrative credentials.
How do I fix CVE-2022-3203?
To mitigate CVE-2022-3203, disable Telnet access to the device if possible and ensure it is isolated from sensitive networks.
What devices are affected by CVE-2022-3203?
CVE-2022-3203 affects the ORing net IAP-420(+) with firmware version 2.0m.
Can CVE-2022-3203 be permanently disabled?
No, CVE-2022-3203 cannot have the Telnet server permanently disabled, as it is enabled by default.
What credentials are exposed in CVE-2022-3203?
CVE-2022-3203 exposes hardcoded administrative credentials that reset to defaults with each reboot.