Rapiscan | Default Password
Executive Summary
The issue of default passwords in Rapiscan systems—specifically the Rapiscan 622XR X-ray scanner—came to prominence in 2020 following a vulnerability disclosure by security researcher Billy Rios. The discovery highlighted a critical and persistent failure in the "security by obscurity" model: relying on hidden, hardcoded credentials to protect sensitive operational technology (OT). While the vulnerability allowed for significant system manipulation, the vendor’s initial response sparked a wider conversation about the balance between device security and physical safety regulations in critical infrastructure.
If you are locked out of a critical security X-ray or metal detector, it is recommended to consult the specific Operator's Manual for your unit's serial number or contact their Global Support team LAURUS Systems contact details for a specific regional Rapiscan service center? Rapiscan 6xx XR Security X-ray System Operator's Manual * Rev. * ECN # Issue Date. * Name. * Comments. LAURUS Systems MetorNet 3 Pro Web | Security Management - Rapiscan Systems
What Rapiscan Says (Officially)
Rapiscan’s official stance has evolved. In a 2020 security advisory (RSSA-2020-01), the company stated: rapiscan default password
The password, if it existed, could grant unauthorized access to the Rapiscan's core database, potentially exposing sensitive information about its users, its operational parameters, and worse still, allowing the hackers to manipulate the system for their malicious intents.
In the cargo hub, Jamal choked on his cold coffee. A message appeared on his screen—from the machine itself. No, from someone inside the machine. Executive Summary The issue of default passwords in
Part 1: What is "Rapiscan"?
Before diving into passwords, we must understand the ecosystem. Rapiscan Systems (now part of OSI Systems, Inc.) produces a wide range of security detection products, including:
Mara had two choices: close the browser and pretend she saw nothing, or do the one thing the Rapiscan manual never mentioned. If you are locked out of a critical
“They ship these things out of the factory with the same keys, same passwords, same everything,” Gerry had said. “admin / admin. Or if it’s the older firmware, ‘service’ with a blank password. Don’t lose it, kid. It’s the skeleton key to the kingdom.”
However, hundreds (if not thousands) of legacy units remain in service. Airports and government agencies often run equipment for 10–15 years due to the high cost of replacement. A Rapiscan 518 X-ray unit installed in 2007 is likely still running its original firmware – and its original default password.