CVE-2022-47732
In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and download it, revealing admin hash, allowing, once cracked, to login inside the Configuration Panel, otherwise, replacing the hash in the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and download it, revealing admin hash, allowing, once cracked, to login inside the Configuration Panel, otherwise, replacing the hash in the archive and restoring it on the device which will change admin password granting access to the device.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-916
- Affected
- yeastar/n824 firmware · yeastar/n412 firmware
- Source
- cve@mitre.org
References
- https://www.swascan.com/security-advisory-yeastar-n412-and-n824-configuration-panel/Exploit, Technical Description, Third Party Advisory
- https://www.yeastar.com/n-series-analog-phone-system/Product, Vendor Advisory
- https://www.swascan.com/security-advisory-yeastar-n412-and-n824-configuration-panel/Exploit, Technical Description, Third Party Advisory
- https://www.yeastar.com/n-series-analog-phone-system/Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.