CVE-2018-10532 describes a critical vulnerability in EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices, where hardcoded root SSH credentials ("oelinux123") are present in the "core_app" binary. This allows an unauthenticated attacker on the local network to gain root access via SSH, leading to a complete compromise of confidentiality, integrity, and availability, and bypassing security features like AP Isolation. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable with low attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
hh70_e1_02.00_19CPE matchmatch criteria | cpe:2.3:o:ee:4gee_firmware:hh70_e1_02.00_19:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.