CVE-2019-25291 PUBLISHED

INIM Electronics Smartliving SmartLAN/G/SI <=6.x Hard-coded Credentials Vulnerability

Assigner: VulnCheck
Reserved: 06.01.2026 Published: 07.01.2026 Updated: 08.01.2026

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor INIM Electronics s.r.l.
Product Smartliving SmartLAN/G/SI
Versions
  • Version <=6.x is affected
  • Version 505 is affected
  • Version 515 is affected
  • Version 1050 is affected
  • Version 1050/G3 is affected
  • Version 10100L is affected
  • Version 10100L/G3 is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • Use of Hard-coded Credentials CWE