Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
http://en.hongdian.com/Products/Details/H8922 | product vendor advisory |
https://ssd-disclosure.com/ssd-advisory-hongdian-h8922-multiple-vulnerabilities/ | third party advisory exploit |