packetstormsecurity.com
http://packetstormsecurity.com/files/151802/Teracue-ENC-400-Command-Injection-Missing-Authentication.html CVE-2018-20220
HIGH
Teracue ENC-400 - Command Injection / Missing Authentication
Record summary
CVE-2018-20220 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTeracue ENC-400 - Command Injection / Missing AuthenticationExploitDB exploitby Stephen ShkardoonNot analyzed1 file
References
4seclists.org
http://seclists.org/fulldisclosure/2019/Feb/48 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-20220 zxsecurity.co.nz
https://zxsecurity.co.nz/research.html