← Vulnerability feed

Vulnerability record · CVE-2023-5222 · published 27 September 2023

CVE-2023-5222: Viessmann Vitogate 300 web interface hard-coded password

Viessmann · Vitogate 300 Firmware

The Viessmann Vitogate 300 web management interface (up to 2.1.3.0) contains a hard-coded password in the isValidUser function of /cgi-bin/vitogate.cgi. Anyone who knows the embedded credential can authenticate to the device without a legitimate account. The vendor was contacted but did not respond, so no fixed version is identified in the record.

9.8 CVSS 3.1 Critical EPSS 75% · top 0.5% CWE-259 · Hard-coded password
9.8CVSS 3.1 base score, v2 5.8
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240364. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no privileges or interaction required, a public exploit, and a very high EPSS score, combined with no confirmed vendor fix.

What it is

The Viessmann Vitogate 300 web management interface (up to 2.1.3.0) contains a hard-coded password in the isValidUser function of /cgi-bin/vitogate.cgi. Anyone who knows the embedded credential can authenticate to the device without a legitimate account. The vendor was contacted but did not respond, so no fixed version is identified in the record.

Impact

An attacker gains full administrative access to the Vitogate 300 web interface, with high impact to confidentiality, integrity and availability per the CVSS vector. From there the device can be reconfigured or used as a foothold into the connected building automation network.

Attack surface

Reachable over the network via HTTP to /cgi-bin/vitogate.cgi; the CVSS vector shows no privileges and no user interaction required. The only barrier is knowing or guessing the hard-coded credential.

Exploitation

A public exploit write-up exists (GitHub reference tagged Exploit) and the record states the exploit has been disclosed and may be used. The CVE is not in CISA KEV, but EPSS is very high at roughly 0.745 (99.5th percentile), indicating elevated likelihood of exploitation.

What to do

  • Apply a vendor firmware update for Vitogate 300 if and when Viessmann releases one; the record notes the vendor did not respond, so confirm availability directly.
  • If no patch exists, isolate the Vitogate 300 web interface from untrusted networks and restrict access to a dedicated management VLAN with allow-listed source addresses.
  • Disable or block remote access to /cgi-bin/vitogate.cgi where the management interface is not required, and place it behind an authenticating reverse proxy.
  • Rotate any credentials or integrations that rely on the device and monitor for unauthorized configuration changes.
  • Treat the device as untrusted: segment it from building automation and corporate networks and log all management sessions.

Detection

  • Monitor web server or network logs for requests to /cgi-bin/vitogate.cgi, especially authentication attempts from unexpected source IPs.
  • Alert on successful logins to the Vitogate web interface outside maintenance windows or from non-management networks.
  • Baseline and alert on configuration changes to the device (network settings, user accounts, forwarding rules) via syslog or configuration diffing.
  • Scan internal networks for exposed Vitogate 300 management interfaces reachable from untrusted segments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/Push3AX/vul/blob/main/viessmann/Vitogate300_HardcodedPassword.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.240364 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.240364 Permissions RequiredThird Party AdvisoryVDB Entry
https://github.com/Push3AX/vul/blob/main/viessmann/Vitogate300_HardcodedPassword.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.240364 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.240364 Permissions RequiredThird Party AdvisoryVDB Entry

Track CVE-2023-5222 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2023-5222), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.