S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 10, 2025

CVE-2025-26793 Scanner

CVE-2025-26793 Scanner - Default Credentials vulnerability in FREEDOM Administration

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-26793
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' PII. NOTE: the Supplier's perspective is that the "vulnerable systems are not following manufacturers' recommendations to change the default password."

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Enterphone MESHby Hirsch
0
Updated Sep 9, 2026View on NVD →
Detail

FREEDOM Administration is a web-based graphical user interface (GUI) configuration panel for Hirsch Enterphone MESH systems. These systems are used primarily in apartment buildings across Canada and the U.S. to manage entry systems. Property administrators use this software to control and monitor access to buildings, providing convenient and centralized management for building security. The interface allows administrators to set up system parameters, view logs, and manage user access in real time. Despite its capabilities, the software's reliance on default credentials creates significant security risks if not properly managed. As such, it is critical for system administrators to follow recommended practices to ensure the security of the system.

The default credential vulnerability in FREEDOM Administration poses serious security risks. Default login credentials (username: freedom, password: viscount) are not prompted to be changed upon initial setup, compromising the integrity of the system. As these credentials are publicly known, attackers can exploit them to gain access to sensitive information and control over the systems. This vulnerability allows unauthorized individuals to manage access to multiple buildings. Ensuring the change of default credentials should be a priority to safeguard against unauthorized access.

Technically, the vulnerability is due to hard-coded default credentials within FREEDOM Administration. The vulnerable endpoint is the mesh.webadmin.MESHAdminServlet, where users can log in using the default credentials. The vulnerability primarily affects the login process, where an attacker can authenticate by submitting a POST request containing these credentials. If successful, the attacker gains administrator-level access to the system, with the potential to manage the administration panel and access data. This flaw is exacerbated by the lack of a mechanism prompting administrators to change default credentials, which must be carried out manually.

When exploited, this vulnerability can have significant ramifications, including unauthorized access to sensitive personal information of building residents. Attackers can alter, delete, or exfiltrate critical data, manipulate system settings, and interrupt services, leading to potentially severe privacy and operational impacts. Moreover, control over the system could be leveraged to gain physical access to facilities, posing additional security and safety concerns for residents. The potential for widespread exploitation necessitates immediate action to mitigate risks associated with this oversight.

REFERENCES

Solution Advice
  • Change the default credentials immediately upon setup to strong, unique passwords.
  • Implement multi-factor authentication to add an extra layer of security during login.
  • Ensure that administrators are prompted to change default credentials as part of the configuration process.
  • Regularly audit and review security configurations and access logs to detect unauthorized access attempts.
  • Provide administrators with training on the importance of secure credential management and software updates.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-26793 Scanner - Default Credentials vulnerability in FREEDOM Administration | S4E