漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NetMan 204 Hard-coded Backdoor Credentials
Vulnerability Description
NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which due to lax parameter validation can be shortened to /cgi-bin/login.cgi?username=eurek%20eurek) to obtain administrator privileges, allowing them to alter device configuration, enable the telnet/SSH services, and reset local user credentials.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
RIELLO UPS NetMan 信任管理问题漏洞
Vulnerability Description
RIELLO UPS NetMan是意大利RIELLO UPS公司的一款网络适配器。 Riello UPS NetMan 204存在信任管理问题漏洞,该漏洞源于包含硬编码后门账户,用户名和密码为eurek,未经身份验证的远程攻击者可通过cgi-bin/login.cgi端点进行身份验证,获取管理员权限,从而更改设备配置、启用telnet/SSH服务并重置本地用户凭据。
CVSS Information
N/A
Vulnerability Type
N/A