漏洞关键信息 EDB-ID: 51460 CVE: N/A Author: LiquidWorm Type: Remote Platform: Hardware Date: 2023-05-23 Vulnerable App: Screen SFT DAB 600/C EDB Verified: No Vendor: DB Elettronica Telecomunicazioni SpA Product Web Page: https://www.screen.it https://www.dbbroadcast.com https://www.dbbroadcast.com/products/radio/sft-dab-series-compact-air/ Affected Version: Firmware: 1.9.3 BIOS firmware: 7.1 (Apr 19 2021) GUI: 2.46 FPGA: 169.55 UC: 6.15 Summary: Screen's new radio DAB Transmitter has an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this to gain access to sensitive information, including usernames and source IP addresses. Desc: The vulnerability allows an attacker to access sensitive information by sending a specially crafted request. Tested On: Keil-EWEB/2.1 MontaVista Linux Carrier Grade eXpress (CGX) Vulnerability Discovered By: Gjoko 'LiquidWorm' Krstic @zeroscience Advisory ID: ZSL-2023-5776 Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5776.php Example Exploit Command: