216.73.217.22

CVE-2015-10148

· Published 03/04/2026 22:16 · Modified 03/04/2026 22:16

Labels: CVE-2015-10148 2026-04-03CVE-2015-10148CWE-321[email protected]

Essential information

Published
03/04/2026 22:16
Modified
03/04/2026 22:16
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept encrypted management communications. Attackers can perform man-in-the-middle attacks, impersonate devices, and expose sensitive information by leveraging the shared default cryptographic keys across multiple devices.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hirschmann / hilcos cpe:2.3:a:hirschmann:hilcos:8.80:*:*:*:*:*:*:*
hirschmann / openbat cpe:2.3:a:hirschmann:openbat:*:*:*:*:*:*:*:*
hirschmann / wlc cpe:2.3:a:hirschmann:wlc:*:*:*:*:*:*:*:*
hirschmann / bat300 cpe:2.3:a:hirschmann:bat300:*:*:*:*:*:*:*:*
hirschmann / bat54 cpe:2.3:a:hirschmann:bat54:*:*:*:*:*:*:*:*
hirschmann / openbat cpe:2.3:a:hirschmann:openbat:<9.10:*:*:*:*:*:*:*

References