PT-2018-18779 · Intelbras · Telefone Ip Tip200/200 Lite

Anhax0R

·

Publicado

2018-03-25

·

Atualizado

2021-09-09

·

CVE-2018-9010

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intelbras TELEFONE IP TIP200/200 LITE version 60.0.75.29
Description The issue allows remote authenticated admins to read arbitrary files via the "/cgi-bin/cgiServer.exx" page parameter, which is vulnerable to absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.
Recommendations For version 60.0.75.29, change the default admin password to prevent unauthorized access and consider restricting access to the "/cgi-bin/cgiServer.exx" page to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-9010

Produtos afetados

Telefone Ip Tip200/200 Lite