Hard-Coded Keys and Open Doors: Critical Flaws Found in PrismX AP Controllers
ID: 5c507980-af66-537c-97bf-06db8bc5781a
STIX ID: report--5c507980-af66-537c-97bf-06db8bc5781a
Feed Name: securityonline.info
This advisory details three vulnerabilities in Browan PrismX MX100 AP Controller: a critical hard-coded credentials flaw (CVE-2026-1221, CVSS 9.8) enabling unauthenticated remote database access, and two command injection vulnerabilities (CVE-2026-1222, CVSS 7.2; CVE-2026-1223, CVSS 4.9) requiring authentication. Devices running firmware prior to 1.03.23.01 are affected; Browan has released firmware 1.03.23.01 to address these issues and administrators are urged to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
