Use of hard-coded credentials in FlexAir - CVE-2019-7672
Published: August 30, 2019
FlexAir
Detailed vulnerability description
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to the flash version of the web interface contains a hard-coded username and password within the SWF file. A remote authenticated attacker can access the affected system using the hard-coded credentials and escalate privileges on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.