IM
IronMonkey Threat Research

CVE-2025-7740 HIGH

Published: 2026-01-28 | Last Modified: 2026-04-15 | Status: Deferred

Description

Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attacker to use an admin account created during product deployment.

Additional Descriptions (1)

Una vulnerabilidad de credenciales por defecto existe en el producto SuprOS. Si se explota, esto podrĂ­a permitir a un atacante local autenticado usar una cuenta de administrador creada durante el despliegue del producto.

CVSS Metrics

Base Score: 8.8 (HIGH)

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorLOCAL
Attack ComplexityLOW
Attack RequirementsPRESENT
Privileges RequiredLOW
User InteractionNONE
Vulnerability ConfidentialityHIGH
Vulnerability IntegrityHIGH
Vulnerability AvailabilityHIGH
Subsequent ConfidentialityHIGH
Subsequent IntegrityHIGH
Subsequent AvailabilityHIGH

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Primary
en CWE-1392
Notification
Message here