vendor:
Platinum 4410 Router
by:
Nitesh Surana
6.5
CVSS
MEDIUM
UPnP Credential Exposure
287
CWE
Product Name: Platinum 4410 Router
Affected Version From: P4410-V2-1.34H
Affected Version To: P4410-V2-1.34H
Patch Exists: NO
Related CWE: CVE-2020-25988
CPE: h:gxgroup:platinum_4410_router
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows/Kali
2020
Genexis Platinum 4410 Router 2.1 – UPnP Credential Exposure
This exploit uses the upnpy library to discover UPnP devices on the network and access a specific service on the device by its ID. The 'X_GetAccess' action is then executed which returns a dictionary containing the cleartext password of 'admin' user.
Mitigation:
Disable UPnP on the router and use strong passwords for the admin account.