CVE-2025-55049

9.1

Baicells · NEUTRINO430

The Baicells NEUTRINO430 device uses a default cryptographic key, which may allow an unauthenticated attacker to compromise encrypted communications or access sensitive data.

Executive summary

A critical vulnerability involving the use of hardcoded default cryptographic keys in Baicells NEUTRINO430 hardware poses a significant risk of unauthorized data interception.

Vulnerability

The device employs a default cryptographic key (CWE-1394), which is accessible to unauthenticated attackers. This flaw facilitates the potential decryption of sensitive traffic or unauthorized authentication bypass.

Business impact

The presence of a default cryptographic key represents a failure in secure configuration, significantly increasing the risk of man-in-the-middle attacks and data exposure. With a CVSS score of 9.1, this vulnerability is critical, as it allows for the total compromise of confidentiality and integrity without requiring user interaction or prior authentication.

Remediation

Immediate Action: Contact the vendor (Baicells) immediately to obtain the latest firmware update that replaces the hardcoded cryptographic keys.

Proactive Monitoring: Monitor network traffic for unusual patterns or attempts to handshake using legacy or default key parameters.

Compensating Controls: Isolate the affected devices within a restricted management VLAN and use internal firewalls to limit exposure to trusted sources only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The use of default cryptographic keys is a high-severity security oversight that undermines the entire security posture of the affected device. Administrators must prioritize the deployment of firmware updates provided by Baicells to rotate these keys and prevent potential unauthorized access to sensitive network communications.