CVE-2025-34034 is a hardcoded credential vulnerability in the Blue Angel Software Suite by 5vtechnologies, affecting embedded Linux systems. Attackers can leverage undisclosed default accounts to gain administrative access to the device's web interface, even with low privileges or unauthenticated access. This vulnerability has a CVSS score of 8.8 (HIGH), indicating a severe risk with high impact on confidentiality, integrity, and availability. While exploitation evidence was observed by the Shadowserver Foundation on 2025-01-26 UTC, there is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:5vtechnologies:blue_angel_software_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.