CVE-2024-29844

D

efault credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password.

Configurations

Configuration 1 (hide)

cpe:2.3:a:cs-technologies:evolution:*:*:*:*:*:*:*:*

History

10 Dec 2025, 17:39

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:a:cs-technologies:evolution:*:*:*:*:*:*:*:*
First Time Cs-technologies evolution
Cs-technologies
References () https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiple-vulnerabilities.html - () https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiple-vulnerabilities.html - Third Party Advisory

21 Nov 2024, 09:08

Type Values Removed Values Added
References () https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiple-vulnerabilities.html - () https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiple-vulnerabilities.html -

25 Sep 2024, 23:15

Type Values Removed Values Added
Summary (en) Default credentials on the Web Interface of Evolution Controller 2.x (123 and 123) allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password. (en) Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password.

Information

Published : 2024-04-15 00:15

Updated : 2025-12-10 17:39


NVD link : CVE-2024-29844

Mitre link : CVE-2024-29844

CVE.ORG link : CVE-2024-29844


JSON object : View

Products Affected
CWE
CWE-1392

Use of Default Credentials

NVD-CWE-Other