CVE-2016-6553 details a critical vulnerability in Nuuo NT-4040 Titan firmware NT-4040_01.07.0000.0015_1120, where devices ship with easily guessable, non-random default credentials (admin:admin and localdisplay:111111). This allows an unauthenticated remote attacker to gain privileged access, leading to complete compromise of the device (CVSS 9.8 Critical). While not listed in CISA KEV and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness. Despite the lack of active exploitation evidence, the high FAUCET Risk Score of 93/100 underscores the severe risk posed by this easily exploitable weakness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
nt-4040_01.07.0000.0015_1120CPE matchmatch criteria | cpe:2.3:o:nuuo:nt-4040_titan_firmware:nt-4040_01.07.0000.0015_1120:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.