Cisco Hard-codes Insecurity

No one said it was easy to develop enterprise-class software. Surely while testing something as complex as a centralized wireless management infrastructure, you've got to make some shortcuts for testing purposes. But to then leave those intact in the shipping...

April 9, 2004

1 Min Read
Network Computing logo

No one said it was easy to develop enterprise-class software. Surely while testing something as complex as a centralized wireless management infrastructure, you've got to make some shortcuts for testing purposes. But to then leave those intact in the shipping product? Oh boy.

A default username/password pair is present in all releases of the Wireless LAN Solution Engine (WLSE) and Hosting Solution Engine (HSE) software. A user who logs in using this username has complete control of the device. This username cannot be disabled. There is no workaround.

SUBSCRIBE TO OUR NEWSLETTER
Stay informed! Sign up to get expert advice and insight delivered direct to your inbox

You May Also Like


More Insights