CRITICAL🇵🇱 Wersja polska

CVE-2024-42639

CVSS 9.8v3.1pub. 2024-08-16upd. 2025-05-27

H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.

🤖 AI Analysis
How it works

The manufacturer embedded a fixed, immutable password for the root account in the firmware, stored in the /etc/shadow file. The vulnerability classified as CWE-259 (Use of Hard-coded Password) means that this password is identical across all device instances with the given firmware version. An attacker who discovers this password (e.g., through firmware image analysis) can log in as root on any vulnerable device.

Impact

An attacker gains full administrative (root) access to the device, allowing complete takeover of the router, modification of network configuration, eavesdropping on network traffic, and potential use of the device as an entry point for further attacks on the network.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Additionally, it is recommended to restrict access to the device management interface exclusively to trusted IP addresses and isolate the device from unauthorized network segments until the patch is deployed.

Who is affected

H3C GR1100-P firmware version v100R009

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • H3c Gr1100 P

    HW
    H3C
    all versions
  • H3c Gr1100 P Firmware

    OS
    H3C
    100r009
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-60262CRITICAL9.8PL ✓same vendor

Błędna konfiguracja vsftpd w H3C M102G i BA1500L — przejęcie uprawnień root

CVE-2024-57480CRITICAL9.8PL ✓same vendor

Buffer overflow w H3C N12 — RCE przez brak walidacji długości danych

CVE-2024-57471CRITICAL9.8PL ✓same vendor

Buffer overflow w H3C N12 — RCE przez sieć bezprzewodową 2.4G

CVE-2024-57473CRITICAL9.8PL ✓same vendor

Buffer overflow w H3C N12 – RCE przez funkcję edycji adresu MAC

CVE-2024-57479CRITICAL9.8PL ✓same vendor

Buffer overflow w H3C N12 — zdalne wykonanie kodu przez funkcję aktualizacji MAC