First published: Sun Mar 25 2018(Updated: )
Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intelbras Tip200 Firmware | =60.0.75.29 | |
Intelbras TIP200 | ||
Intelbras Tip200lite Firmware | =60.0.75.29 | |
Intelbras Tip200lite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-9010 is high with a CVSS score of 7.2.
Remote authenticated admins can exploit CVE-2018-9010 by reading arbitrary files via the /cgi-bin/cgiServer.exx page parameter.
Yes, in some cases, authentication can be achieved via the admin account with its default admin password.
No, Intelbras TIP200 is not affected by CVE-2018-9010.
To fix CVE-2018-9010, update the firmware to version 60.0.75.29 or above.