CVE-2019-25291
7.5INIM Electronics · Smartliving SmartLAN/G/SI
INIM Electronics Smartliving SmartLAN/G/SI control panels utilize persistent hard-coded credentials within their Linux distribution image, allowing unauthorized system access.
Executive summary
Multiple INIM Electronics Smartliving control panel models are vulnerable to unauthorized system access due to the presence of unchangeable, hard-coded credentials.
Vulnerability
The device firmware contains hard-coded credentials for Telnet, SSH, and FTP services that cannot be modified by the end user. An unauthenticated attacker can leverage these credentials to gain full administrative access to the underlying Linux operating system.
Business impact
Successful exploitation allows an attacker to gain complete control over the affected security and home automation control panels. This compromise can lead to full loss of confidentiality, integrity, and availability of the security system, potentially allowing physical security bypasses or unauthorized monitoring of the premises. Given the CVSS score of 7.5, this represents a high-severity risk that requires immediate attention, particularly for systems exposed to the internet.
Remediation
Immediate Action: Restrict network access to the affected devices by placing them behind a robust firewall and disabling remote management interfaces (Telnet, SSH, FTP) if they are not strictly required for operations.
Proactive Monitoring: Review system access logs for any unauthorized login attempts or suspicious activity originating from unknown IP addresses.
Compensating Controls: Deploy a Virtual Private Network (VPN) for any necessary remote administrative access to ensure that the vulnerable management interfaces are never exposed directly to the public internet.
Exploitation status
Public Exploit Available: Yes, a technical write-up and proof-of-concept exploit are available via Exploit-DB (EDB-ID: 47763).
Analyst recommendation
The presence of unchangeable, hard-coded credentials presents a significant security flaw that cannot be resolved through standard password updates. Organizations utilizing these INIM Electronics devices must prioritize isolating these systems from public network segments immediately. If remote management is required, it must be tunneled through secure, authenticated gateways to prevent exploitation by external actors.
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Vulnerability Advisory Third-party advisory
- Exploit Database Entry 47763 Exploit / PoC
- Packet Storm Security Exploit File Exploit / PoC
- IBM X-Force Vulnerability Exchange Entry Vulnerability database entry
- INIM Vendor Homepage