H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.
The manufacturer embedded a fixed, immutable password for the root account in the firmware, stored in the /etc/shadow file. The vulnerability classified as CWE-259 (Use of Hard-coded Password) means that this password is identical across all device instances with the given firmware version. An attacker who discovers this password (e.g., through firmware image analysis) can log in as root on any vulnerable device.
An attacker gains full administrative (root) access to the device, allowing complete takeover of the router, modification of network configuration, eavesdropping on network traffic, and potential use of the device as an entry point for further attacks on the network.
Apply patches available from the manufacturer according to the references. Additionally, it is recommended to restrict access to the device management interface exclusively to trusted IP addresses and isolate the device from unauthorized network segments until the patch is deployed.
H3C GR1100-P firmware version v100R009
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HH3c Gr1100 P
HWH3Call versionsH3c Gr1100 P Firmware
OSH3C100r009
Related vulnerabilities
Błędna konfiguracja vsftpd w H3C M102G i BA1500L — przejęcie uprawnień root
Buffer overflow w H3C N12 — RCE przez brak walidacji długości danych
Buffer overflow w H3C N12 — RCE przez sieć bezprzewodową 2.4G
Buffer overflow w H3C N12 – RCE przez funkcję edycji adresu MAC
Buffer overflow w H3C N12 — zdalne wykonanie kodu przez funkcję aktualizacji MAC