PT-2018-18779 · Intelbras · Telefone Ip Tip200/200 Lite
Anhax0R
·
Published
2018-03-25
·
Updated
2021-09-09
·
CVE-2018-9010
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intelbras TELEFONE IP TIP200/200 LITE version 60.0.75.29
Description
The issue allows remote authenticated admins to read arbitrary files via the "/cgi-bin/cgiServer.exx" page parameter, which is vulnerable to absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.
Recommendations
For version 60.0.75.29, change the default admin password to prevent unauthorized access and consider restricting access to the "/cgi-bin/cgiServer.exx" page to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telefone Ip Tip200/200 Lite