CVE-2020-24285
INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion
Record summary
CVE-2020-24285 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHINTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File InclusionCVSS 7.5
INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 is vulnerable to information disclosure, allowing unauthenticated attackers to access sensitive device information and configuration data via a direct request to the /cgi-bin/export_settings.sh endpoint.
Impact
Authenticated attackers can read arbitrary files from the device including configuration files and credentials, potentially leading to complete device compromise.
Remediation
Update the device firmware to the latest version provided by INTELBRAS.
Source: ProjectDiscovery