Record summary

CVE-2020-24285 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHINTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File InclusionCVSS 7.5

INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 is vulnerable to information disclosure, allowing unauthenticated attackers to access sensitive device information and configuration data via a direct request to the /cgi-bin/export_settings.sh endpoint.

Impact

Authenticated attackers can read arbitrary files from the device including configuration files and credentials, potentially leading to complete device compromise.

Remediation

Update the device firmware to the latest version provided by INTELBRAS.

WeaknessesCWE-200
Authorsritikchaddha
Template tagscvecve2020intelbrastelefonetip200exposurelfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Shodan: html:"/cgi-bin/cgiServer.exx"
FOFA: body="/cgi-bin/cgiServer.exx"

Source: ProjectDiscovery

References

3