LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2015-10148

CVE-2015-10148 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: April 3, 2026

Hirschmann HiLCOS - Weak Cryptography

Published: April 3, 2026Updated: April 3, 2026Remote Exploitable

Overview

Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 < 8.80 and OpenBAT < 9.10 contain a weak cryptography vulnerability caused by identical default SSH and SSL keys that cannot be changed, letting unauthenticated remote attackers perform man-in-the-middle attacks and intercept encrypted management communications, exploit requires use of default keys.

Severity & Score

Severity: High
CVSS Score: 8.2

Impact

Unauthenticated attackers can intercept and decrypt management communications, impersonate devices, and expose sensitive information.

Mitigation

Update to versions 8.80 or later for BAT300, BAT54 and WLC, and 9.10 or later for OpenBAT or latest available versions.

Details

CVE ID
CVE-2015-10148
Severity
High
CVSS Score
8.2
Type
weak_cryptography
Status
new

CWE

  • CWE-321

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N