github.com
https://github.com/anselal/antminer-monitor CVE-2021-40903
CRITICAL
Antminer Monitor 0.5.0 - Authentication Bypass
Record summary
CVE-2021-40903 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBAntminer Monitor 0.5.0 - Authentication BypassExploitDB exploitby VulnzNot analyzed1 file
Repository PoCs
GitHubvulnz/CVE-2021-40903Repository PoCby vulnzStars: 0Not analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-40903 packetstormsecurity.com
https://packetstormsecurity.com/files/164048/Antminer-Monitor-0.5.0-Authentication-Bypass.html exploit-db.com
https://www.exploit-db.com/exploits/50267