The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session. <a href"http://cwe.mitre.org/data/definitions/798.html" target"_blank">CWE-798: Use of Hard-coded Credentials</a>
Publication date: Mon, 21 Dec 2015 17:59:00 +0000