Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper webserver configuration on Plum IK-401 devices with firmware before 1.02 allows an attacker (with network access to the device) to obtain the configuration file, including hashed credential data. Successful exploitation could allow access to hashed credential data with a single unauthenticated GET request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Plum Ik-401 访问控制错误漏洞
Vulnerability Description
Plum Ik-401是德国Plum公司的一个用于工业环境中的4G调制解调器/路由器。 Plum IK-401 1.02之前版本存在安全漏洞,该漏洞源于固件在的Plum IK-401设备上的不适当的webserver配置允许攻击者可利用该漏洞(通过网络访问该设备)获取配置文件,包括散列的凭证数据。成功的利用可以允许通过一个未经身份验证的GET请求访问散列的凭据数据。
CVSS Information
N/A
Vulnerability Type
N/A