Wire · technology
Exposed BMCs hand out password hashes before login
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 28 July 2026 · Fusion42 review
Researchers discovered that 36,872 baseboard management controllers (BMCs) exposed on the public internet leak password hashes before authentication via CVE-2013-4786, with two-thirds recoverable offline; factory-preset passwords on Supermicro and HPE hardware crack in hours to minutes using commodity GPUs.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 2 sources have reported it.
◆ ◆ The Wire takeaway
Your data centre infrastructure sits on exposed hardware you didn't know was listening. If you run servers on Supermicro or HPE, someone outside your network can grab the factory password hash and crack it in an hour with eight GPUs—then own the machine below your operating system's sight line.
◆ Coverage
2 sources · 28 Jul 2026
◆ Related on Wire
◆ Topics