ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://csirt.divd.nl/CVE-2025-36747/ |
|
History
Sat, 13 Dec 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced. | |
| Title | Hardcoded FTP Credentials within the firmware | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: DIVD
Published: 2025-12-13T08:16:25.804Z
Updated: 2025-12-13T08:16:25.804Z
Reserved: 2025-04-15T21:54:36.813Z
Link: CVE-2025-36747
No data.
Status : Received
Published: 2025-12-13T16:16:53.710
Modified: 2025-12-13T16:16:53.710
Link: CVE-2025-36747
No data.