PatchSiren cyber security CVE debrief
CVE-2024-41161 Vonets CVE debrief
A Use of Hard-coded Credentials vulnerability in Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters allows unauthenticated remote attackers to bypass authentication using hard-coded administrator credentials. The affected accounts cannot be disabled, leaving affected devices permanently exposed to unauthorized administrative access until firmware remediation is available.
- Vendor
- Vonets
- Product
- VAR1200-H
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-08-01
- Original CVE updated
- 2024-08-01
- Advisory published
- 2024-08-01
- Advisory updated
- 2024-08-01
Who should care
Operational technology security teams, industrial network administrators, critical infrastructure operators using Vonets wireless bridging equipment, and organizations with remote or distributed sites relying on these devices for network connectivity.
Technical summary
The vulnerability exists due to hard-coded administrator credentials embedded in Vonets firmware. An unauthenticated attacker with network access to the device's administrative interface can authenticate using these credentials, gaining full administrative control. The credentials cannot be changed or disabled through normal configuration means. Affected firmware versions 3.3.23.6.9 and prior span sixteen product models across multiple Vonets product lines including VAR1200-H/L, VAR600-H, VAP11AC, VAP11G variants, VAP11S variants, VAR11N-300, VAP11N-300, VBG1200, and VGA-1000.
Defensive priority
HIGH
Recommended defensive actions
- Contact Vonets support ([email protected]) to request security patch status and remediation timeline
- Inventory all Vonets VAR, VAP, VBG, and VGA series devices in operational technology environments
- Segment affected devices from untrusted networks; restrict administrative interface access to dedicated management VLANs
- Monitor for unauthorized administrative access attempts to device management interfaces
- Consider replacement of affected devices if vendor remediation is not forthcoming
- Apply CISA ICS recommended practices for defense-in-depth architecture
- Review network traffic for anomalous connections to Vonets device management ports
Evidence notes
CISA published advisory ICSA-24-214-08 on 2024-08-01 documenting hard-coded credentials in Vonets firmware versions 3.3.23.6.9 and prior. The vendor has not responded to CISA coordination requests. Sixteen product variants are affected across the VAR, VAP, VBG, and VGA product families.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-41161 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-41161
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-41161 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-41161
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-214-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.