Environment
https://113.44.152.62/
Reproduction link
https://113.44.152.62/
Steps to reproduce
-
Navigate to https://113.44.152.62/
-
Enter admin for the username and admin for the password.
-
Press “Login”.
-
Observe that you are immediately redirected to the administrative dashboard.
Impact:
-
Full device compromise, including the ability to view/manipulate settings, network configuration, and potentially user data.
-
Could be used as a pivot point for further attacks on the internal network.
Remediation:
-
Change the default password immediately to a strong, unique one.
-
If remote management is not needed, disable it or restrict access via firewall rules.
-
Enable login attempt rate limiting or lockout policies.
What is expected?
The admin interface should either disable default accounts or force a password change upon first login. It should not be accessible with the well‑known factory credentials admin:admin.
What is actually happening?
When navigating to https://113.44.152.62/ and entering admin / admin, the user is immediately logged in and granted unrestricted administrative privileges. No password change is enforced, and the default credentials are still active.
Environment
https://113.44.152.62/
Reproduction link
https://113.44.152.62/
Steps to reproduce
Navigate to https://113.44.152.62/
Enter admin for the username and admin for the password.
Press “Login”.
Observe that you are immediately redirected to the administrative dashboard.
Impact:
Full device compromise, including the ability to view/manipulate settings, network configuration, and potentially user data.
Could be used as a pivot point for further attacks on the internal network.
Remediation:
Change the default password immediately to a strong, unique one.
If remote management is not needed, disable it or restrict access via firewall rules.
Enable login attempt rate limiting or lockout policies.
What is expected?
The admin interface should either disable default accounts or force a password change upon first login. It should not be accessible with the well‑known factory credentials admin:admin.
What is actually happening?
When navigating to https://113.44.152.62/ and entering admin / admin, the user is immediately logged in and granted unrestricted administrative privileges. No password change is enforced, and the default credentials are still active.