You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Exploit Title: Default Root Password and Remote Enrollment on FingerTec Devices
2
+
# Date: 12-01-2016
3
+
# Exploit Author: Daniel Lawson
4
+
# Contact: http://twitter.com/fang0654
5
+
# Website: https://digital-panther.com
6
+
# Category: physical access control
7
+
8
+
1. Description
9
+
10
+
Almost all FingerTec Access Control devices are running with open telnet, with a hardcoded default root password. Additionally, it is trivial to enroll a new administrative user on the device with a pin code or RFID card that will allow opening the door.
11
+
12
+
2. Proof of Concept
13
+
14
+
Login to telnet with the credentials: root / founder88
0 commit comments