The credentials required to access the device's web...
Moderate severity
Unreviewed
Published
Jan 7, 2026
to the GitHub Advisory Database
•
Updated Jan 7, 2026
Description
Published by the National Vulnerability Database
Jan 7, 2026
Published to the GitHub Advisory Database
Jan 7, 2026
Last updated
Jan 7, 2026
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials