9.8
CVSSv3

CVE-2018-11094

Published: 15/05/2018 Updated: 22/06/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.

Vulnerable Product Search on Vulmon Subscribe to Product

intelbras ncloud_300_firmware 1.0

Exploits

# coding: utf-8 # Exploit Title: Intelbras NCloud Authentication bypass # Date: 16/05/2018 # Exploit Author: Pedro Aguiar - pedroaguiar@kryptuscom # Vendor Homepage: wwwintelbrascombr/ # Software Link: wwwintelbrascombr/empresarial/wi-fi/para-sua-casa/roteadores/ncloud # Version: 10 # Tested on: Linux # CVE : CVE-2018-11094 # ...
Intelbras NCLOUD 300 version 10 suffers from an authentication bypass vulnerability ...