关键信息 漏洞描述 - 漏洞类型: Hard-Coded Credentials - 受影响设备: VideoFlow Digital Video Protection (DVP) 2.10 - 厂商: VideoFlow Ltd. - 产品网页: http://www.video-flow.com - 受影响版本: 2.10 (X-Prototype-Version: 1.6.0.2) 系统信息 - 系统: DVP Protector - 版本: 1.40.0.15(R) May 5 2015 05:27:05 - 镜像版本: 3.07i 漏洞描述 - 影响: Authenticated remote code execution - 测试环境: CentOS release 5.6 (Final) 和 CentOS release 5.10 (Final) - 发现者: Gjoko 'LiquidWorm' Krstic (@zeroscience) 默认凭据 - Web管理: - admin:admin - oper:oper - private:private - public:public - devel:devel - Hard-Coded SSH凭据: - root:videoflow - mom:$1$CGgdGXXG$0FmyyKMzcHgkKnUTZi5r 参考 - Advisory ID: ZSL-2018-5455 - Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5455.php