GPU VulnDB

Database/Control plane, storage & DevOps

Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who can

CVE-2017-16727Control plane, storage & DevOpsICSA-17-355-01curated

Impact

The device ships with an empty default password, so anyone who can reach it on the network can log in as an unauthorized user with no credential at all and take over the serial device server.

Who can reach it

No authentication required — just network reachability to a device still running the default (blank) password.

What to do

Firmware upgrade past 1.11 plus setting a real administrator password on every device — the firmware fix stops shipping the box in an unauthenticated state, but existing deployed units also need someone to actually set a password during the upgrade. Track this as a fleet-wide credential-rotation project, not just a flash.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.