CVE-2025-55049
9.1Baicells · NEUTRINO430
The Baicells NEUTRINO430 device uses a default cryptographic key, which may allow an unauthenticated attacker to compromise encrypted communications or access sensitive data.
Executive summary
A critical vulnerability involving the use of hardcoded default cryptographic keys in Baicells NEUTRINO430 hardware poses a significant risk of unauthorized data interception.
Vulnerability
The device employs a default cryptographic key (CWE-1394), which is accessible to unauthenticated attackers. This flaw facilitates the potential decryption of sensitive traffic or unauthorized authentication bypass.
Business impact
The presence of a default cryptographic key represents a failure in secure configuration, significantly increasing the risk of man-in-the-middle attacks and data exposure. With a CVSS score of 9.1, this vulnerability is critical, as it allows for the total compromise of confidentiality and integrity without requiring user interaction or prior authentication.
Remediation
Immediate Action: Contact the vendor (Baicells) immediately to obtain the latest firmware update that replaces the hardcoded cryptographic keys.
Proactive Monitoring: Monitor network traffic for unusual patterns or attempts to handshake using legacy or default key parameters.
Compensating Controls: Isolate the affected devices within a restricted management VLAN and use internal firewalls to limit exposure to trusted sources only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The use of default cryptographic keys is a high-severity security oversight that undermines the entire security posture of the affected device. Administrators must prioritize the deployment of firmware updates provided by Baicells to rotate these keys and prevent potential unauthorized access to sensitive network communications.