EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
EyesOfNetwork · EyesOfNetwork
Date added (CISA)
2021-11-03
Remediation due
2022-05-03
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.