CVE-2022-45444
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database. This could allow a remote attacker to login to the database with unrestricted access.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.57%
- CWE
- CWE-259
- Published
- 2023-01-18
- Last modified
- 2026-03-13
Affected products
- Sewio RTLS Studio
Weakness type
Related vulnerabilities
- CVE-2024-7332 — TOTOLINK CP450 Telnet Service product.ini hard-coded password
- CVE-2023-5222 — Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
- CVE-2012-5862 — Sinapsi eSolar Hard-Coded Password
- CVE-2023-2645 — USR USR-G806 Web Management Page hard-coded password
- CVE-2014-2363 — Morpho Itemiser 3 Hard-Coded Credential
- CVE-2025-8730 — Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
- CVE-2025-11126 — Apeman ID71 system.ini hard-coded credentials
- CVE-2024-32741 — A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded pa