Advertisement






Across DR-810 ROM-0 - Backup File Disclosure

CVE Category Price Severity
CVE-2020-27130 CWE-200 $800 High
Author Risk Exploitation Type Date
Author Unknown High Remote 2019-01-12
CPE
cpe:cpe:/h:across:dr-810
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019010131

Below is a copy:

Across DR-810 ROM-0 - Backup File Disclosure
#Exploit Title: Across DR-810 ROM-0 - Backup File Disclosure(Sensitive Information)
#Date: 2019-01-11
#Exploit Author: SajjadBnz
#My Email: [email protected]
#Vendor Homepage: http://www.ac.i8i.ir/
#Version: DR-810
#Tested on: DR-810
#RomPager/4.07 UPnP/1.0

[+] About
==========
this hardware is a SIM card modem , This modem is being installed in Iran and sold with the SIM card
i8i.ir An internet site that sells products like SIM-card modems This modem has sold countless And on the main page of the site wrote: 

SIM modems are used in a variety of ways and for similar uses, and depending on the features and quality, they have a variety of prices.
In this site, you will be familiar with the five modem and router sim-modem groups, which you can consult with us to choose the best option for you, and choose one of them.

[+] Rom-0 Backup File Disclosure
=================================
A dangerous vulnerability present on many network devices which are using
RomPager.The rom-0 file contains sensitive information such as the router password.
There is a disclosure in which anyone can download that file without any authentication by
a simple GET request.

[+] POC
========
just add /rom-0 to your target address
rom-0 Backup File will be downloaded

http://target/rom-0

then you can Decompressed the file and get password

Tnx All

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum