CVE-2023-43261: Milesight Routers – Information Disclosure

CVE-2023-43261: Milesight Routers - Information Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2023-43261: Milesight Routers – Information Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-43261: Milesight Routers – Information Disclosure

漏洞描述

A critical security vulnerability has been identified in Milesight Industrial Cellular Routers, compromising the security of sensitive credentials and permitting unauthorized access. This vulnerability stems from a misconfiguration that results in directory listing being enabled on the router systems, rendering log files publicly accessible. These log files, while containing sensitive information such as admin and other user passwords (encrypted as a security measure), can be exploited by attackers via the router's web interface. The presence of a hardcoded AES secret key and initialization vector (IV) in the JavaScript code further exacerbates the situation, facilitating the decryption of these passwords. This chain of vulnerabilities allows malicious actors to gain unauthorized access to the router.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享