A vulnerability exists in the Credential Manager...
High severity
Unreviewed
Published
Sep 1, 2026
to the GitHub Advisory Database
•
Updated Sep 2, 2026
Description
Published by the National Vulnerability Database
Sep 1, 2026
Published to the GitHub Advisory Database
Sep 1, 2026
Last updated
Sep 2, 2026
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.
References