Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6617
Reference (s):
- BID:70927
- URL: http://www.securityfocus.com/bid/70927
- BUGTRAQ:20141105 CVE-2014-6617 Softing FG-100 Backdoor Account
- URL: http://www.securityfocus.com/archive/1/533902/100/0/threaded
- http://packetstormsecurity.com/files/128976/Softing-FG-100-PB-Hardcoded-Backdoor.html