APC UPS for Home and Office Forum
Support forum to share knowledge about installation and configuration of APC offers including Home Office UPS, Surge Protectors, UTS, software and services.
Posted: 2021-06-29 04:51 AM . Last Modified: 2024-03-22 12:25 AM
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-29 04:51 AM . Last Modified: 2024-03-22 12:25 AM
Hello!
I just bought APC Back-UPS HS 500 and I have problem with web interface.
IP address is assigned through DHCP.
When I access web interface there is login prompt and I can login with default username and password.
Problem is when I access web interface and don't enter password I can se all web pages without any login prompt.
I can access STATUS, CONFIGURATION, MAINTENANCE and what is worse ABOUT page where there is information like MAC address and serial number.
It is huge security risk because anyone could access that info and get backdoor credentials
from your forum at https://community.exchange.se.com/t5/APC-UPS-for-Home-and-Office-Forum/bd-p/home-office-forum !???
- Firmware revision: l1
- Web firmware revision: l5
- UPS date of manufacture (mm-dd-yyyy): 10-29-2010
- Battery replacement date (mm-dd-yyyy): 10-29-2010
Please help, thank you!
Greetings from Croatia.
Mladen Santic
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-29 04:51 AM . Last Modified: 2024-03-22 12:25 AM
i didnt realize that was possible since i dont work with that product often but the product only supports access from the local subnet, you cannot put it on the internet. that still can be a risk i understand though. not sure if anyone else has any comments on that?
does it do it by hitting the back button where the credentials are being cached?
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-29 04:51 AM . Last Modified: 2024-03-22 12:25 AM
i didnt realize that was possible since i dont work with that product often but the product only supports access from the local subnet, you cannot put it on the internet. that still can be a risk i understand though. not sure if anyone else has any comments on that?
does it do it by hitting the back button where the credentials are being cached?
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.