RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password. An unauthenticated physical attacker can use the hard-coded default password during system reboot triggered by other user, to acquire partial system information such as serial number and server information.
2022-11-29T04:15:10.407
2024-11-21T07:07:19.910
Modified
CVSSv3.1: 2.1 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | realtek | rtl8111ep-cg_firmware | ≤ 3.0.0.2019090 | Yes |
Operating System | realtek | rtl8111ep-cg_firmware | 5.0.10 | Yes |
Hardware | realtek | rtl8111ep-cg | - | No |
Operating System | realtek | rtl8111fp-cg_firmware | ≤ 3.0.0.2019090 | Yes |
Operating System | realtek | rtl8111fp-cg_firmware | 5.0.10 | Yes |
Hardware | realtek | rtl8111fp-cg | - | No |