CVE-2019-15497: Blackbox Icompel Firmware
Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
Affected products
- Blackbox Icompel Firmware: from 9.2.3, up to and including 11.1.4
- Onelan Net-Top-Box Firmware: from 9.2.3, up to and including 11.1.4
Published 2019-08-26. Last modified 2026-06-17.