vendor:
All Devices
by:
Todor Donev and Òîäîð Äîíåâ
9,8
CVSS
HIGH
Remote Hardware Access
284
CWE
Product Name: All Devices
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2013
Seowonintech all device remote root exploit v2
This exploit allows an attacker to gain root access on a Seowonintech device. The exploit is triggered by sending a GET request to the device's /cgi-bin/diagnostic.cgi page, which will then allow the attacker to send a GET request to the /cgi-bin/system_config.cgi page, granting them root access.
Mitigation:
Ensure that all devices are running the latest version of firmware and that all security patches are applied.