CVE-2025-34034
BaseFortify
Publication date: 2025-06-24
Last updated on: 2025-11-20
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| 5vtechnologies | blue_angel_software_suite | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a hardcoded credential issue in the Blue Angel Software Suite used on embedded Linux systems. The software contains multiple default and hardcoded user accounts that are not publicly documented. These accounts allow attackers who are unauthenticated or have low privileges to gain administrative access to the device's web interface.
How can this vulnerability impact me? :
The vulnerability can allow unauthorized attackers to gain administrative access to the device's web interface, potentially leading to full control over the device, unauthorized configuration changes, data exposure, or disruption of services.