CVE-2022-36159 concerns a hardcoded, weak hash password for the root user in the /etc/shadow file of Contec FXA3200 (v1.13 and earlier) and related FXA series devices. This vulnerability allows an unauthenticated attacker on the adjacent network to easily crack the password and gain full control of the Wireless LAN Manager interface, enabling actions like sniffing traffic or injecting malware. While rated High severity (CVSS 8.8) due to its critical impact on confidentiality, integrity, and availability, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention and article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.13.00CPE matchmatch criteria | cpe:2.3:o:contec:fxa3000_firmware:*:*:*:*:*:*:*:* | ||
<= 1.13.00CPE matchmatch criteria | cpe:2.3:o:contec:fxa3020_firmware:*:*:*:*:*:*:*:* | ||
<= 1.13.00CPE matchmatch criteria | cpe:2.3:o:contec:fxa3200_firmware:*:*:*:*:*:*:*:* | ||
< 1.39.00CPE matchmatch criteria | cpe:2.3:o:contec:fxa2000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.