CVE-2019-25291

7.5

INIM Electronics · Smartliving SmartLAN/G/SI

INIM Electronics Smartliving SmartLAN/G/SI control panels utilize persistent hard-coded credentials within their Linux distribution image, allowing unauthorized system access.

Executive summary

Multiple INIM Electronics Smartliving control panel models are vulnerable to unauthorized system access due to the presence of unchangeable, hard-coded credentials.

Vulnerability

The device firmware contains hard-coded credentials for Telnet, SSH, and FTP services that cannot be modified by the end user. An unauthenticated attacker can leverage these credentials to gain full administrative access to the underlying Linux operating system.

Business impact

Successful exploitation allows an attacker to gain complete control over the affected security and home automation control panels. This compromise can lead to full loss of confidentiality, integrity, and availability of the security system, potentially allowing physical security bypasses or unauthorized monitoring of the premises. Given the CVSS score of 7.5, this represents a high-severity risk that requires immediate attention, particularly for systems exposed to the internet.

Remediation

Immediate Action: Restrict network access to the affected devices by placing them behind a robust firewall and disabling remote management interfaces (Telnet, SSH, FTP) if they are not strictly required for operations.

Proactive Monitoring: Review system access logs for any unauthorized login attempts or suspicious activity originating from unknown IP addresses.

Compensating Controls: Deploy a Virtual Private Network (VPN) for any necessary remote administrative access to ensure that the vulnerable management interfaces are never exposed directly to the public internet.

Exploitation status

Public Exploit Available: Yes, a technical write-up and proof-of-concept exploit are available via Exploit-DB (EDB-ID: 47763).

Analyst recommendation

The presence of unchangeable, hard-coded credentials presents a significant security flaw that cannot be resolved through standard password updates. Organizations utilizing these INIM Electronics devices must prioritize isolating these systems from public network segments immediately. If remote management is required, it must be tunneled through secure, authenticated gateways to prevent exploitation by external actors.

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.