blog.kos-lab.com
https://blog.kos-lab.com/Hello-World CVE-2018-11094
CRITICAL
Intelbras NCLOUD 300 1.0 - Authentication bypass
Record summary
CVE-2018-11094 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIntelbras NCLOUD 300 1.0 - Authentication bypassExploitDB exploitby Pedro AguiarNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-11094 44637exploit
https://www.exploit-db.com/exploits/44637