Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6xp5-7rcx-xfgx | Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login |
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sipcapture
Sipcapture homer |
|
| Vendors & Products |
Sipcapture
Sipcapture homer |
Wed, 07 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue. | |
| Title | Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T17:44:17.215Z
Reserved: 2026-07-13T17:09:57.573Z
Link: CVE-2026-62252
Updated: 2026-10-07T17:44:11.235Z
Status : Awaiting Analysis
Published: 2026-10-07T17:16:56.467
Modified: 2026-10-08T21:09:00.643
Link: CVE-2026-62252
No data.
OpenCVE Enrichment
Updated: 2026-10-09T08:15:27Z
Github GHSA