Back

CRITICAL

Hardcoded FTP Credentials within the firmware

Published Dec 13, 2025

Description

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner DIVD
Published Dec 13, 2025
Updated Dec 16, 2025
Reserved Apr 15, 2025
CISA Vulnrichment
Updated Dec 15, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a