CVE-2019-25291 CRITICAL

CVE-2019-25291: INIM Electronics Smartliving SmartLAN/G/SI <=6.x Hard-coded Credentials Vulnerability

Vendor Inim Electronics S.r.l.
Product Smartliving SmartLAN/G/SI
Weakness CWE-798 · Hardcoded credentials
Published January 7, 2026
Last update March 23, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.

Key dates

02Disclosure timeline

January 7, 2026 CVE published
March 23, 2026 Record updated