CVE-2023-1778 is a critical vulnerability affecting GajShield Data Security Firewall firmware versions prior to v4.28 (excluding v4.21). It stems from insecure default credentials, allowing remote attackers to log in as a superuser via the web management interface or exposed SSH port. This flaw enables arbitrary command execution with administrative privileges, posing a severe risk to affected systems. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable remotely without authentication or user interaction. While no active exploitation, public exploit code, or significant community discussion has been observed, the vendor has addressed the issue by forcing users to change default passwords.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.21CPE matchmatch criteria | cpe:2.3:o:gajshield:data_security_firewall_firmware:*:*:*:*:*:*:*:* | ||
>= 4.22, < 4.28CPE matchmatch criteria | cpe:2.3:o:gajshield:data_security_firewall_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.