FaceSentry Access Control System 6.4.8 Remote SSH Root Access
Posted by deepcore on July 2, 2019 – 3:12 pm
FaceSentry Access Control System version 6.4.8 facial biometric access control appliance ships with hard-coded and weak credentials for SSH access on port 23445 using the credentials wwwuser:123456. The root privilege escalation is done by abusing the insecure sudoers entry file.
Post a reply
You must be logged in to post a comment.