jeyaseelans.medium.com
https://jeyaseelans.medium.com/cve-2020-35338-9e841f48defa CVE-2020-35338
CRITICALNuclei
Wireless Multiplex Terminal Playout Server <=20.2.8 - Default Credential Detection
Record summary
CVE-2020-35338 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALWireless Multiplex Terminal Playout Server <=20.2.8 - Default Credential DetectionCVSS 9.8
Wireless Multiplex Terminal Playout Server <=20.2.8 has a default account with a password of pokon available via its web administrative interface.
Impact
An attacker can exploit this vulnerability to gain unauthorized access to the server.
Remediation
Change the default credentials to strong and unique ones.
WeaknessesCWE-798
AuthorsJeya Seelan
Template tagscvecve2020wmtdefault-loginmobileviewpointvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:mobileviewpoint:wireless_multiplex_terminal_playout_server:*:*:*:*:*:*:*:*
https://jeyaseelans.medium.com/cve-2020-35338-9e841f48defa https://nvd.nist.gov/vuln/detail/CVE-2020-35338 https://www.mobileviewpoint.com/ https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35338 mobileviewpoint.com
https://www.mobileviewpoint.com/