CVE-2021-37555
Last modified
CVE-2021-37555 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g., tar and nc).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trixie | Tx9 Automatic Food Dispenser Firmware | 3.2.57 |
References
- http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-296520Third Party Advisory
- http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-296520Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-37555?
How severe is CVE-2021-37555?
How do I fix CVE-2021-37555?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-3755Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-37550In JetBrains YouTrack before 2021.2.16363, time-unsafe compa…7.5
- CVE-2021-37551In JetBrains YouTrack before 2021.2.16363, system user passw…5.3
- CVE-2021-37552In JetBrains YouTrack before 2021.2.17925, stored XSS was po…5.4
- CVE-2021-37553In JetBrains YouTrack before 2021.2.16363, an insecure PRNG …7.5
- CVE-2021-37554In JetBrains YouTrack before 2021.3.21051, a user could see …4.3
- CVE-2021-37556A SQL injection vulnerability in reporting export in Centreo…8.8
- CVE-2021-37557A SQL injection vulnerability in image generation in Centreo…8.8
- CVE-2021-37558A SQL injection vulnerability in a MediaWiki script in Centr…9.8
- CVE-2021-3756libmysofa is vulnerable to Heap-based Buffer Overflow9.8
- CVE-2021-37560MediaTek microchips, as used in NETGEAR devices through 2021…8.8
- CVE-2021-37561MediaTek microchips, as used in NETGEAR devices through 2021…8.8
Are you affected by CVE-2021-37555?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
