PT-2018-18779 · Intelbras · Telefone Ip Tip200/200 Lite

Anhax0R

·

Published

2018-03-25

·

Updated

2021-09-09

·

CVE-2018-9010

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intelbras TELEFONE IP TIP200/200 LITE version 60.0.75.29
Description The issue allows remote authenticated admins to read arbitrary files via the "/cgi-bin/cgiServer.exx" page parameter, which is vulnerable to absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.
Recommendations For version 60.0.75.29, change the default admin password to prevent unauthorized access and consider restricting access to the "/cgi-bin/cgiServer.exx" page to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-9010

Affected Products

Telefone Ip Tip200/200 Lite