216.73.216.233

CVE-2025-34034

· Published 24/06/2025 01:15 · Modified 24/06/2025 22:15

Labels: CVE-2025-34034 2025-06-24CVE-2025-34034CWE-798[email protected]

Essential information

Published
24/06/2025 01:15
Modified
24/06/2025 22:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
blue angel software / blue angel software suite cpe:2.3:a:blue_angel_software:blue_angel_software_suite:*:*:*:*:*:*:*:*
linux / linux cpe:2.3:o:linux:linux:*:*:*:*:*:*:*:*

References