eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.
The vulnerability results from the use of default, widely known authentication credentials (CWE-1392), which are not invalidated or changed during the device installation and configuration process. The manufacturer does not enforce mandatory password change after the first server startup. As a result, any attacker with network access to the server's interface can log in using 'user:user' or 'admin:admin' accounts, completely bypassing authentication mechanisms.
An attacker gains full administrative access to the configuration and control functions of the smart home system, enabling manipulation of settings, takeover of connected devices, and potential violation of user privacy and physical security.
Default passwords for all accounts (particularly 'user' and 'admin') must be immediately changed to strong, unique passwords immediately after installation. Patches available from the manufacturer should be applied according to references, and network access to the server's management interface should be restricted exclusively to trusted hosts (e.g., through firewall or network segmentation).
Jung-Group eNet SMART HOME Server in versions 2.2.1 and 2.3.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XJung Group Enet Smart Home
APPJung-Group2.2.12.3.1
Related vulnerabilities
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount...
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword...
Privilege escalation w eNet SMART HOME Server przez metodę setUserGroup
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticat...
JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attacke...