CVE-2019-12776 describes a critical hard-coded SSH backdoor present in ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 devices running specific firmware versions. This vulnerability allows an unauthenticated attacker to gain remote root access via SSH and SCP by using a hard-coded private key. With a CVSS score of 9.8 (CRITICAL), the attack requires no user interaction and has high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the presence of a hard-coded backdoor represents a severe security flaw. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
70044CPE matchmatch criteria | cpe:2.3:o:enttec:datagate_mk2_firmware:70044:05032019-482:*:*:*:*:*:* | ||
70044CPE matchmatch criteria | cpe:2.3:o:enttec:storm_24_firmware:70044:05032019-482:*:*:*:*:*:* | ||
70044CPE matchmatch criteria | cpe:2.3:o:enttec:pixelator_firmware:70044:05032019-482:*:*:*:*:*:* | ||
70044CPE matchmatch criteria | cpe:2.3:o:enttec:e-streamer_mk2_firmware:70044:05032019-482:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.