Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.
References
Link Resource
https://github.com/delikely/advisory/tree/main/GARO Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-03-21T10:38:37

Updated: 2022-03-21T10:38:37

Reserved: 2021-12-27T00:00:00


Link: CVE-2021-45877

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-21T11:15:10.670

Modified: 2022-03-28T17:06:25.510


Link: CVE-2021-45877

JSON object: View

cve-icon Redhat Information

No data.

CWE