CVE-2004-0391

CRITICAL

Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users,...

Affects 2 products across 1 vendor.

BCS7.48
CVSS 2.010.0
EPSS4.6%
Percentile91th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2004. A critical vulnerability affects Cisco systems (CVE-2004-0391). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2004-GLOBAL-007896-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-0391?
This vulnerability was disclosed in 2004. A critical vulnerability affects Cisco systems (CVE-2004-0391). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2004-0391?
CVE-2004-0391 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 4.6%.
Is CVE-2004-0391 actively exploited?
No confirmed active exploitation of CVE-2004-0391 as of 2026-05-30.
How do I remediate CVE-2004-0391?
Priority: MEDIUM. Advisory: http://www.ciac.org/ciac/bulletins/o-111.shtml PSIRT: [email protected]
What systems are affected by CVE-2004-0391?
CVE-2004-0391 affects: Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2004-0391
BSIDBS-2004-GLOBAL-007896-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2004-06-01
Last Modified2026-04-16
ICS Relevance75%
Domains
NETWORK-INFRA
SourceNVD
Official Description

Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Wireless Lan Solution Engine
Cisco Hosting Solution Engine
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8099 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashee327c55f6eb8d4cfb7ba05c581dd0fe1e149fea6506da8613b25ff4e88cb4322502c0da6fe6223edbcef574fd7c8924043dea6397e3528d3eb46066cca23cff
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2008-0029 10.0 Cisco Application Velocity System (AVS) before 5.1.0 is installed with defaul... CVE-2014-0659 10.0 The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N rout... CVE-2014-0648 10.0 The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 ... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →