EXPOSURES › CVE-2020-8657
CVE-2020-8657
HIGH ⌖ ON CISA KEV · EXPLOITEDEyesOfNetwork shipped with hard-coded API keys allowing attackers to guess admin access tokens.
The vendor used the same API key by default, enabling attackers to calculate or guess admin access tokens. DIB organizations must ensure no default or hard-coded credentials exist in their supply chain, as this directly violates CMMC/NIST 800-171 requirements for access control and system integrity. Immediate action requires replacing default credentials and implementing strict credential rotation policies.
Shame score — Hard-coded credentials are a fundamental, avoidable security failure that directly enables unauthorized access and violates core compliance requirements.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.