The credentials required to access the device's web...
Moderate severity
Unreviewed
Published
Sep 29, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Sep 29, 2025
Published to the GitHub Advisory Database
Sep 29, 2025
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.
References