CVE-2025-1868
MEDIUMAdvanced IP Scanner & Advanced Port Scanner - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-1868. PoCs published by itres-labs.
AI-analyzed exploit summary This repository contains a PHP-based proof-of-concept for CVE-2025-1868, which exploits an NTLM leakage vulnerability in Advanced IP Scanner and Advanced Port Scanner. The PoC triggers an NTLM handshake and extracts domain, user, and workstation information from NTLM Type 3 messages without validating passwords or storing challenges.
Description
Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scanner. It occurs when these applications initiate a network scan, inadvertently sending the NTLM hash of the user performing the scan. This vulnerability can be exploited by intercepting network traffic to a legitimate server or by setting up a fake server, in both local and remote scenarios. This exposure is relevant for both HTTP/HTTPS and SMB protocols.
Exploits (1)
This repository contains a PHP-based proof-of-concept for CVE-2025-1868, which exploits an NTLM leakage vulnerability in Advanced IP Scanner and Advanced Port Scanner. The PoC triggers an NTLM handshake and extracts domain, user, and workstation information from NTLM Type 3 messages without validating passwords or storing challenges.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N