CVE-2012-5862
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.
Scoring
- CVSS base score
- 10
- CVSS vector
- AV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS probability
- 18.26%
- CWE
- CWE-259
- Published
- 2012-11-23
- Last modified
- 2026-03-15
Affected products
- Sinapsi eSolar
- Sinapsi eSolar DUO
- Sinapsi eSolar Light
Weakness type
Related vulnerabilities
- CVE-2024-7332 — TOTOLINK CP450 Telnet Service product.ini hard-coded password
- CVE-2023-5222 — Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
- CVE-2023-2645 — USR USR-G806 Web Management Page hard-coded password
- CVE-2022-45444 — CVE-2022-45444
- CVE-2014-2363 — Morpho Itemiser 3 Hard-Coded Credential
- CVE-2025-8730 — Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
- CVE-2025-11126 — Apeman ID71 system.ini hard-coded credentials
- CVE-2024-32741 — A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded pa