Use of Default Cryptographic Key (CWE-1394)
The product uses a built-in, pre-known cryptographic key instead of a unique key generated during installation or first startup. An attacker possessing knowledge of this default key can decrypt protected data, sign their own messages or tokens in a way accepted by the system. A network attack vector without authentication or user interaction requirements means that the exploit can be conducted remotely and fully automatically.
An attacker can gain unauthorized access to protected information (confidentiality breach) and modify or forge authentication data, tokens, or other protected resources (integrity breach).
Patches available from the manufacturer should be applied according to references. Additionally, all default cryptographic keys must be immediately changed to unique randomly generated values, and where possible — enforce key rotation and invalidate sessions based on compromised keys.
Versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N