Vulnerabilities
Vulnerable Software
Bosch:  >> B426 Firmware  Security Vulnerabilities
This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which was released on June 2019.
CVSS Score
8.0
EPSS Score
0.003
Published
2021-06-18
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
CVSS Score
8.8
EPSS Score
0.001
Published
2021-06-18


Contact Us

Shodan ® - All rights reserved