Advisory: EntryPass N5200 Credentials Disclosure
EntryPass N5200 Active Network Control Panels offer an HTTP service on TCP port 80. It appears that only the first character of a requested URL's path is relevant to the web server. By enumerating all one-character long URLs on a device, it was determined that URLs starting with a numeric character are used by the web interface, as listed in the following table: http://example.com/0 Index, http://example.com/1 Stylesheet, http://example.com/2 Authentication with Username/Password, http://example.com/3 Session Management, http://example.com/4 Device Status, http://example.com/5 Progressbar Image, http://example.com/6 Logout. The URL http://example.com/2 returns a JavaScript file containing the current administrative username and password in plaintext.