vendor:
CPE7000
by:
Federico Scalco
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: CPE7000
Affected Version From: V02A
Affected Version To: V02A
Patch Exists: NO
Related CWE: N/A
CPE: h:gemtek:cpe7000
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Gemtek CPE7000 – WLTCS-106 Administrator SID Retriever
A vulnerability exists for Gemtek CPE7000 model ID WLTCS-106 which allows unauthenticated remote attackers to retrieve a valid Administrative SID. To obtain an administrative web session inject this SID in your client's cookie with values as follow: userlevel=2;sid=<SID> Tested on Hardware version V02A and Firmware version 01.01.02.082.
Mitigation:
Ensure that authentication is properly implemented and enforced.