CVE-2021-47708
CRITICALCOMMAX Smart Home System CDP-1020n - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47708. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in COMMAX Smart Home IoT Control System CDP-1020n, allowing authentication bypass via the 'id' POST parameter in 'loginstart.asp'. The provided HTTP request includes a classic SQLi payload (' or 1=1--) to bypass authentication.
Description
COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL code through the 'id' parameter in 'loginstart.asp'. Attackers can exploit this by sending a POST request with malicious 'id' values to manipulate database queries and gain unauthorized access.
Exploits (1)
The exploit demonstrates an SQL injection vulnerability in COMMAX Smart Home IoT Control System CDP-1020n, allowing authentication bypass via the 'id' POST parameter in 'loginstart.asp'. The provided HTTP request includes a classic SQLi payload (' or 1=1--) to bypass authentication.
References (5)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N