CVE-2026-82453 PUBLISHED

rust-iot-platform Cleartext Password Storage via User Model

Assigner: VulnCheck
Reserved: 29.08.2026 Published: 29.08.2026 Updated: 29.08.2026

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor iot-ecology
Product rust-iot-platform
Versions Default: unaffected
  • affected from 0 to 5df942ab6bc46a3bf83dbee8c7970554f92c972d (incl.)

Credits

  • Harsh Raj Singhania reporter

References

Problem Types

  • Plaintext Storage of a Password CWE