Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 29 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iot-ecology
Iot-ecology rust-iot-platform |
|
| Vendors & Products |
Iot-ecology
Iot-ecology rust-iot-platform |
Sat, 29 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts. | |
| Title | rust-iot-platform Cleartext Password Storage via User Model | |
| Weaknesses | CWE-256 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T13:47:55.410Z
Reserved: 2026-08-29T13:22:58.931Z
Link: CVE-2026-82453
No data.
Status : Received
Published: 2026-08-29T14:16:38.347
Modified: 2026-08-29T14:16:38.347
Link: CVE-2026-82453
No data.
OpenCVE Enrichment
Updated: 2026-08-29T15:30:05Z
-
CWE-256
Plaintext Storage of a Password