CVE-2020-10275
The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.17%
- CWE
- CWE-261
- Published
- 2020-06-24
- Last modified
- 2026-03-14
Affected products
- Mobile Industrial Robots A/S MiR100
Weakness type
Related vulnerabilities
- CVE-2024-45394 — Secret encryption vulnerable to brute-force attacks
- CVE-2021-21507 — Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versi
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2024-45273 — MB connect line/Helmholz: Weak encryption of configuration file
- CVE-2024-7407 — Weak password encoding in Streamsoft Prestiż
- CVE-2024-8455 — PLANET Technology switch devices - Swctrl service exchanges weakly encoded passwords
- CVE-2022-45099 — Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged lo
- CVE-2023-0525 — Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000