Cisco warns about default account in access point

Spread the love

Network equipment manufacturer Cisco warns that a default account is present in its Aironet 1850 and 1830 access points. This allows an attacker to take over a vulnerable device via ssh.

According to Cisco, the access points are vulnerable if they run a version 8.2.x of its Mobility Express software that is older than version 8.2.111.0. That means versions 8.1 and 8.0 are not vulnerable. The manufacturer reports that it does not matter what configuration the device has and that an attacker must be connected through the network layer. Users are advised to perform an update.

By providing the correct credentials, an attacker can connect to a vulnerable access point via ssh and gain elevated privileges on the system. This allows him to completely take over the device. Cisco focuses on enterprise customers with the two models.

You might also like
Exit mobile version