Digital oscilloscopes that can communicate over the network fail to provide a minimum of security protections and allow unfettered access to unauthorized users. The product analyzed by security researchers at SEC-Consult is the SDS 1202X-E Digital Oscilloscope from Siglent. Among the faults they found were two hardcoded backdoor accounts: ‘root’ and’siglent’ The device has Telnet service turned on and listens on the default TCP port 23. Connecting to the oscilloscope this way grants root access to an attacker on the local network.
Source: https://www.bleepingcomputer.com/news/security/digital-oscilloscope-comes-with-backdoor-accounts-old-software-components/

