CVE-2025-55047
8.4Baicells · SPECTRA LTE-U eNB
The Baicells SPECTRA LTE-U eNB device contains a vulnerability involving the use of hard-coded credentials, which could allow unauthorized access to the system.
Executive summary
A critical vulnerability involving hard-coded credentials in Baicells SPECTRA LTE-U eNB devices poses a significant risk of unauthorized administrative access and system compromise.
Vulnerability
This vulnerability is categorized as CWE-798, which involves the presence of hard-coded credentials within the device firmware. The CVSS vector indicates that an attacker with local, unauthenticated access can achieve full confidentiality, integrity, and availability impact.
Business impact
The presence of hard-coded credentials enables an attacker to bypass authentication mechanisms, potentially gaining complete control over the affected eNB hardware. Given the CVSS score of 8.4, this flaw represents a high-severity risk that could lead to unauthorized data interception, service disruption, or the potential for lateral movement within the network infrastructure.
Remediation
Immediate Action: Contact the vendor for specific security updates or configuration patches to remove or rotate the hard-coded credentials.
Proactive Monitoring: Review system authentication logs for unexpected logins or administrative activity originating from unknown or unusual sources.
Compensating Controls: Isolate affected devices within a restricted management network segment and employ strict firewall rules to limit local access to the device management interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing Baicells SPECTRA LTE-U eNB hardware must prioritize the identification of exposed devices and engage with the vendor to obtain necessary security patches. Due to the nature of hard-coded credentials, this vulnerability cannot be fully mitigated by configuration changes alone, making vendor-provided firmware updates the only permanent resolution.
Sources
Originally found and disclosed by Shahaf Levi, per the CVE Program record.