Knowledge Base  /  Security Advisories

Security Advisory: SMTP Credential Pass-back 

May 16, 2024


Impacted Devices and Firmware:

  • Room Alert 4E, firmware 4.4.0 and earlier
  • Room Alert 3E, firmware 2.4.0 and earlier 
  • Room Alert 12E, firmware 3.3.0 and earlier 
  • Room Alert 32E, firmware 3.3.1 and earlier 
  • Room Alert 3S, firmware 1.10.3 and earlier 
  • Room Alert 12S, firmware 1.10.3 and earlier 
  • Room Alert 32S, firmware 1.10.3 and earlier 


Changing the mail server within the device allows the configured credentials to be sent in plaintext to an attacker via credential pass-back attack.


An individual with administrative access can change the mail server host within the device. An attacker who has obtained administrative access can update the mail server to an attacker controller IP. When the device attempts to authenticate to the mail server, it will pass the previously configured credentials in plaintext to the attacker’s IP.


For users of S-models, upgrade to firmware 1.10.4 or higher which requires SMTP credentials to be re-entered whenever the mail server host is changed. Regardless of the model, AVTECH strongly recommends that users set custom administrative credentials on the device to restrict access to all settings, including SMTP settings. When using E-models, use Room Alert Account or Room Alert Manager, where possible, to send email notifications instead of sending them directly from the device. If the device is not being used to send emails, ensure any SMTP credentials have been removed from the device. 

Room Alert is Made in the USA, ships worldwide from our locations in the US and EU, and has been protecting facilities since 1988.

You may find Windows Command Prompt at the following path:

  • Windows 7 & 8
    Start--> All Programs--> Accessories--> Command Prompt
  • Windows 10
    Start--> All Apps--> Windows System--> Command Prompt

To run Windows Command Prompt as an administrator:

  • Windows 7 & 8
    Right-click on Command Prompt and select Run as administrator.
  • Windows 10
    Right-click on Command Prompt, select More and then select Run as administrator.

Example Polling Method Properties saved in Orion SolarWinds:

If you are using this client, you should configure the general SNMPv3 Credentials, but leave the Read / Write SNMPv3 Credentials section blank.

Room Alert Link- Supported Firmware Updates

Current S modelsCurrent E models
Room Alert 32SRoom Alert 32E
Room Alert 12SRoom Alert 12E
Room Alert 4E
Room Alert 3E

Room Alert Manager - Compatible Devices

The latest version of Room Alert Manager supports only the devices below.

It does not support any legacy Room Alert or TemPageR models.

Current S modelsCurrent E models
Room Alert 32SRoom Alert 32E
Room Alert 12SRoom Alert 12E
Room Alert 3SRoom Alert 4E
Room Alert 3E
Room Alert 3W