Cisco Fixes Hard-coded Credentials, SSH Key Issues

November 5, 2021

Cisco recently released a security update to address two critical vulnerabilities: CVE-2021-34795 which allows attackers to gain access with hard-coded credentials, and CVE-2021-40119 which uses default SSH keys to take over unpatched devices.

The first vulnerability has been found in Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) and may allow a remote attacker to login to the affected device via a debugging account with a default, static password.”

However, the vulnerability is limited in that it can only be exploited by creating a Telnet session with vulnerable devices. Since Telnet is not enabled by default, the number of targets that a threat actor could attack is therefore limited.

The second vulnerability is caused by the re-use of static SSH keys in Cisco Policy Suite installations, allowing a remote attacker to log in to an affected system as the root user.

Cisco’s new software updates automatically generate new SSH keys during installation to address the vulnerability.

For more information, read the original story in Bleeping Computer.

Top Stories

Related Articles

June 9, 2026 Hackers exploited Meta’s AI-powered support chatbot to gain control of Instagram accounts, including several high-profile profiles. Meta more...

June 5, 2026 Security researchers have disclosed a new denial-of-service attack called HTTP/2 Bomb that can overwhelm major web servers more...

May 20, 2026 The Cybersecurity and Infrastructure Security Agency, the arm of the U.S. government tasked with protecting critical infrastructure more...

May 11, 2026 Instructure has restored access to its Canvas learning platform after a cyberattack disrupted service for universities and more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn