The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://cds.thalesgroup.com/en |
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-07 17:16
Updated : 2026-01-08 18:08
NVD link : CVE-2026-22543
Mitre link : CVE-2026-22543
CVE.ORG link : CVE-2026-22543
JSON object : View
Products Affected
No product.
CWE
CWE-261
Weak Encoding for Password
