CVE-2020-28993
HIGHATX miniCMTS200a Broadband Gateway and Pico CMTS <= 2.0 - Unauthenticated Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-28993. PoCs published by Zagros Bingol.
AI-analyzed exploit summary This exploit discloses credentials by fetching the 'user.ini' file from ATX MiniCMTS200a Broadband Gateway 2.0, extracting usernames and MD5 hashes via regex. It leverages an unauthenticated information disclosure vulnerability.
Description
A Directory Traversal vulnerability exists in ATX miniCMTS200a Broadband Gateway through 2.0 and Pico CMTS through 2.0. Successful exploitation of this vulnerability would allow an unauthenticated attacker to retrieve administrator credentials by sending a malicious POST request.
Exploits (1)
This exploit discloses credentials by fetching the 'user.ini' file from ATX MiniCMTS200a Broadband Gateway 2.0, extracting usernames and MD5 hashes via regex. It leverages an unauthenticated information disclosure vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N