CVE detail
CVE-2024-45275
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
Critical and high-severity vulnerabilities that can lead to full device compromise have been found in mbNET.mini and Helmholz industrial routers.
newswww.securityweek.comOct 22, 2024, 11:55 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-45276CVSS 7.5 · High
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
- CVE-2024-45274CVSS 9.8 · Critical
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
- CVE-2024-45273CVSS 8.4 · High
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
- CVE-2024-45271CVSS 8.4 · High
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
- CVE-2025-41681CVSS 4.8 · Medium
A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content.
- CVE-2025-41679CVSS 5.3 · Medium
An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conft…