CVE-2024-43698
Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.44%
- CWE
- CWE-1391
- Published
- 2024-10-22
- Last modified
- 2026-03-13
Affected products
- Kieback&Peter DDC4040e
- Kieback&Peter DDC4020e
- Kieback&Peter DDC4400e
- Kieback&Peter DDC4200e
- Kieback&Peter DDC4002e
- Kieback&Peter DDC4400
- Kieback&Peter DDC4200-L
- Kieback&Peter DDC4200
Weakness type
Related vulnerabilities
- CVE-2026-79679 — Use of Weak Credentials
- CVE-2026-66409 — DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot...
- CVE-2026-66408 — The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords....
- CVE-2026-49852 — joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
- CVE-2026-45363 — `jwt` (Ruby gem) - empty-key HMAC bypass
- CVE-2026-57473 — A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to...
- CVE-2026-47325 — Weak password policy in ProjectsAndPrograms school-management-system
- CVE-2026-4377 — Use of Weak Credentials in D-Link DWR-X1820 router