Skip to content

Latest commit

 

History

History
29 lines (17 loc) · 797 Bytes

File metadata and controls

29 lines (17 loc) · 797 Bytes

ipTIME A2004 Unauthorized Access Vulnerability 2

0x01 Vulnerability description

A vulnerability is in the '/login/hostinfo2.cgi' page of the ipTIME A2004, version is 12.17.0.This flaw allows remote attackers to obtain sensitive information,without undergoing any authentication process. It leaked some settings of this device.

http://target/login/hostinfo2.cgi

0x02 Affected version

ipTIME A2004

0x03 PoC verification

Visiting the corresponding page directly through the browser can reveal the version information about the device, which is included in the Response Headers.

image-20241115101220838

0x04 Acknowledgement

Shuanunio

0X05 CVE ID

CVE-2024-57064