Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on affected devices.
History

Mon, 05 Jan 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Cypress
Cypress ctm-200
Cypress ctm-one
Linux
Linux linux
Vendors & Products Cypress
Cypress ctm-200
Cypress ctm-one
Linux
Linux linux

Fri, 02 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
Description Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on affected devices.
Title Cypress Solutions CTM-200/CTM-ONE 1.3.6 Hard-coded Credentials Remote Root
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-31T18:39:11.435Z

Updated: 2026-01-02T16:23:14.918Z

Reserved: 2025-12-31T02:09:17.953Z

Link: CVE-2021-47744

cve-icon Vulnrichment

Updated: 2026-01-02T16:20:55.379Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-31T19:15:42.823

Modified: 2025-12-31T20:42:15.637

Link: CVE-2021-47744

cve-icon Redhat

No data.