MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
The system generates values used in the authentication process (e.g., session tokens, nonces, or identifiers) in an insufficiently random or predictable manner. An attacker can predict or reproduce these values without knowledge of the correct authentication credentials. This allows access to the system while bypassing the standard login process.
An unauthenticated attacker can remotely gain full access to the system over the network — affecting confidentiality, integrity, and availability of data and device functions.
Apply patches available from the manufacturer according to the references provided. It is also recommended to restrict network access to the DeviceHub interface exclusively to trusted networks or VPN until the patch is deployed.
Milesight DeviceHub — versions specified in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCanonical Ubuntu
OSCanonical20.04Milesight Devicehub
APPMilesight3.0.1-r1
Related vulnerabilities
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)
SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE
RCE jako root w OpenSMTPD przez command injection w polu MAIL FROM
RCE w Exim — heap-based buffer overflow w obsłudze komendy EHLO