Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a specific endpoint (/cwi/ajax_request/get_data.php), an authenticated attacker (even with a low-privileged account like guest) can retrieve the hashed passwords for the admin, manager, and guest accounts. This significantly weakens the system's security posture, as these hashes could be cracked offline, granting attackers administrative access to the device.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
2wcom IP-4c 安全漏洞
Vulnerability Description
2wcom IP-4c是德国2wcom公司的一款音频编解码设备。 2wcom IP-4c 2.15.5版本存在安全漏洞,该漏洞源于特定端点/cwi/ajax_request/get_data.php存在信息泄露,可能导致攻击者获取管理员、经理和访客账户的哈希密码。
CVSS Information
N/A
Vulnerability Type
N/A