AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amss++ Project
Amss++ Project amss++ Amssplus Amssplus amss Plus |
|
| Vendors & Products |
Amss++ Project
Amss++ Project amss++ Amssplus Amssplus amss Plus |
Fri, 06 Feb 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system. | |
| Title | AMSS++ 4.7 - Backdoor Admin Account | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-06T23:14:07.110Z
Updated: 2026-02-06T23:14:07.110Z
Reserved: 2026-02-03T16:27:45.307Z
Link: CVE-2020-37135
No data.
Status : Awaiting Analysis
Published: 2026-02-07T00:15:54.760
Modified: 2026-02-09T16:08:55.263
Link: CVE-2020-37135
No data.