Report: Latest: CVE-2026-9139 - Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml

Report: Latest: CVE-2026-9139 - Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml

CVE ID :CVE-2026-9139 Published : May 20, 2026, 8:16 p.m. | 25 minutes ago Description :Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing static plaintext credentials in the page source. Unauthenticated attackers with network access can recover administrative credentials directly from the client-side validate() function to obtain full administrative access to the device. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
May 20, 2026
Attack Vector: network