CVE-2018-9010

Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.
References
Link Resource
https://www.exploit-db.com/exploits/44317/ Exploit Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/44317/ Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:intelbras:tip200_firmware:60.0.75.29:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:tip200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:intelbras:tip200lite_firmware:60.0.75.29:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:tip200lite:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:14

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/44317/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/44317/ - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2018-03-25 18:29

Updated : 2024-11-21 04:14


NVD link : CVE-2018-9010

Mitre link : CVE-2018-9010

CVE.ORG link : CVE-2018-9010


JSON object : View

Products Affected

intelbras

  • tip200lite_firmware
  • tip200
  • tip200_firmware
  • tip200lite
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')