CVE-2018-11220
HIGHBitmain Antminer D3, L3+, and S9 Firmware - Remote Command Execution via System Restore Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-11220. PoCs published by CorryL.
AI-analyzed exploit summary This exploit leverages the 'Restore Backup' functionality in Bitmain Antminer devices to achieve remote command execution by uploading a malicious archive containing a reverse shell script. It requires valid credentials and exploits improper input validation in the backup restoration process.
Description
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.
Exploits (1)
This exploit leverages the 'Restore Backup' functionality in Bitmain Antminer devices to achieve remote command execution by uploading a malicious archive containing a reverse shell script. It requires valid credentials and exploits improper input validation in the backup restoration process.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H