CVE-2021-37555
Summary
| CVE | CVE-2021-37555 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-26 21:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g., tar and nc). |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Trixie | Tx9 Automatic Food Dispenser | - | All | All | All |
| Operating System | Trixie | Tx9 Automatic Food Dispenser Firmware | 3.2.57 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Etisk hackning av en smart foderautomat | MISC | urn.kb.se | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.