InfraPower PPS-02-S Q213V1...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary InfraPower Manager PPS-02-S is a FREE built-in GUI of each IP dongle ( IPD-02-S only ) to remotely monitor the connected PDUs. Patented IP Dongle provides IP remote access to the PDUs by a true network IP address chain. Only 1xIP dongle allows access to max. 16 PDUs in daisy chain - which is a highly efficient cient application for saving not only the IP remote accessories cost, but also the true IP addresses required on the PDU management. ### Description InfraPower suffers from a use of hard-coded credentials. The IP dongle firmware ships with hard-coded accounts that can be used to gain full system access (root) using the telnet daemon on port 23. ### Vendor Austin Hughes Electronics Ltd. - http://www.austin-hughes.com ### Affected Version * Q213V1 (Firmware: V2395S) ### Tested On * Linux 2.6.28 (armv5tel) * lighttpd/1.4.30-devel-1321 * PHP/5.3.9 * SQLite/3.7.10 ### PoC `cat /etc/passwd` ``` root:4g.6AafvEPx9M:0:0:root:/:/sbin/root_shell.sh bin:x:1:1:bin:/bin:/bin/sh...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息