NuCom NC-WR744G Console Application hard-coded credentials

CVE Details

Basic Information

Title NuCom NC-WR744G Console Application hard-coded credentials
Type cve
Published 2025-05-31T13:31:04.543Z
Last Seen

Product Information

Vendor NuCom
Product NC-WR744G
Version 8.5.5 Build 20200530.307

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A critical vulnerability in NuCom NC-WR744G 8.5.5 Build 20200530.307 allows remote attackers to exploit hard-coded credentials in the Console Application. The vendor did not respond to early disclosure attempts.
AI Severity Medium
Vendor NuCom
Product NC-WR744G
Affected Version 8.5.5 Build 20200530.307

Additional Information

CVE List
CWE List CWE-798, CWE-259
Bulletin Family
Source Data NuCom NC-WR744G 8.5.5 Build 20200530.307

Source Information

Source Data NuCom NC-WR744G 8.5.5 Build 20200530.307
Source Link

Description

A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation of the argument CMCCAdmin/useradmin/CUAdmin leads to hard-coded credentials. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Score Summary

Base Score: 5.3 (MEDIUM)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.