CVE-2022-36222

Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nokia:fastmile_firmware:3tg00118abad52:*:*:*:*:*:*:*
cpe:2.3:h:nokia:fastmile:-:*:*:*:*:*:*:*

History

28 Dec 2022, 21:11

Type Values Removed Values Added
CWE CWE-798
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4
CPE cpe:2.3:o:nokia:fastmile_firmware:3tg00118abad52:*:*:*:*:*:*:*
cpe:2.3:h:nokia:fastmile:-:*:*:*:*:*:*:*
First Time Nokia fastmile Firmware
Nokia fastmile
Nokia
References (MISC) https://eddiez.me/hacking-the-nokia-fastmile-pt2/#identical-super-admin-passwords - (MISC) https://eddiez.me/hacking-the-nokia-fastmile-pt2/#identical-super-admin-passwords - Exploit, Third Party Advisory

21 Dec 2022, 19:23

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-21 19:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-36222

Mitre link : CVE-2022-36222

CVE.ORG link : CVE-2022-36222


JSON object : View

Products Affected

nokia

  • fastmile
  • fastmile_firmware
CWE
CWE-798

Use of Hard-coded Credentials