CVE-2018-9010

Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.
References
Link Resource
https://www.exploit-db.com/exploits/44317/ Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:intelbras:tip200:-:*:*:*:*:*:*:*
cpe:2.3:o:intelbras:tip200_firmware:60.0.75.29:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:intelbras:tip200lite:-:*:*:*:*:*:*:*
cpe:2.3:o:intelbras:tip200lite_firmware:60.0.75.29:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-03-25 18:29

Updated : 2021-09-09 01:26


NVD link : CVE-2018-9010

Mitre link : CVE-2018-9010

CVE.ORG link : CVE-2018-9010


JSON object : View

Products Affected

intelbras

  • tip200
  • tip200_firmware
  • tip200lite_firmware
  • tip200lite
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')