CVE-2026-1221
9.8BROWAN COMMUNICATIONS · PrismX MX100 AP controller
BROWAN COMMUNICATIONS PrismX MX100 AP controller contains hard-coded database credentials in its firmware, enabling unauthenticated remote attackers to gain unauthorized database access.
Executive summary
A critical vulnerability in the BROWAN COMMUNICATIONS PrismX MX100 AP controller allows unauthenticated remote attackers to bypass security via hard-coded credentials, leading to total system compromise.
Vulnerability
The device suffers from a Use of Hard-coded Credentials (CWE-798) vulnerability. Unauthenticated remote attackers can leverage these credentials to gain full access to the underlying database.
Business impact
This vulnerability carries a CVSS score of 9.8, indicating a critical risk to organizational infrastructure. Successful exploitation allows unauthorized parties to access sensitive data, modify system configurations, or potentially pivot into internal network segments, resulting in severe operational disruption and loss of confidentiality.
Remediation
Immediate Action: Update the firmware of the affected PrismX MX100 AP controller to version v1.03.23.01 or later immediately.
Proactive Monitoring: Review device access logs for unauthorized administrative logins or anomalous database connection attempts originating from unknown IP addresses.
Compensating Controls: Restrict management interface access to trusted administrative subnets via firewall rules to prevent remote exploitation attempts from untrusted network locations.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from security administrators. Given that the flaw is remotely exploitable without authentication, organizations must prioritize patching the affected firmware to the latest version to eliminate the hard-coded credential risk. Failure to apply this update leaves the device exposed to full unauthorized access.
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Analyst report written
- Fix documented version 1.03.23.01 per CVE record