vendor:
TELEFONE IP TIP200/200 LITE
by:
Todor Donev
7.5
CVSS
HIGH
Pre-Auth Remote Arbitrary File Read
284
CWE
Product Name: TELEFONE IP TIP200/200 LITE
Affected Version From: 60.61.75.15
Affected Version To: 60.61.75.15
Patch Exists: YES
Related CWE: N/A
CPE: h:intelbras:telefone_ip_tip200/200_lite
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
IntelBras TELEFONE IP TIP200/200 LITE 60.61.75.15 ‘dumpConfigFile’ Pre-Auth Remote Arbitrary File Read
This exploit allows an attacker to read arbitrary files on IntelBras TELEFONE IP TIP200/200 LITE 60.61.75.15 devices without authentication. The attacker can send a specially crafted HTTP request to the vulnerable device in order to read any file on the system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their devices to the latest version.