CVE-2018-11741
CRITICALNEC Univerge SV9100 WebPro Firmware 6.00.00 - Account Information Disclosure via Predictable Session ID
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-11741. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit targets CVE-2018-11742, which involves predictable session IDs and cleartext password storage in NEC Univerge WebPro. It brute-forces session IDs to access the 'Programming Password Setup' page and dumps user credentials.
Description
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.
Exploits (1)
This exploit targets CVE-2018-11742, which involves predictable session IDs and cleartext password storage in NEC Univerge WebPro. It brute-forces session IDs to access the 'Programming Password Setup' page and dumps user credentials.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H