Telesquare SKT LTE Router SDT-CS3B1...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary We introduce SDT-CS3B1 LTE router which is a SKT 3G and 4G LTE wireless communication based LTE router product. ### Description Insecure direct object references occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources and functionalities in the system. ### Vendor Telesquare Co., Ltd. - http://www.telesquare.co.kr ### Affected Version * FwVer: SDT-CS3B1, sw version 1.2.0 * LteVer: ML300S5XEA41_090 1 0.1.0 * Modem model: PM-L300S ### Tested On * lighttpd/1.4.20 ### PoC ``` /home.html << Version and status info leak (firmware, device, type, modem, lte) /index.html << Version and status info leak (firmware, device, type, modem, lte) /nas/smbsrv.shtml << Samba server settings (workgroup, netbios name) /nas/ftpsrv.shtml << FTP settings /wifi2g/basic.shtml << Wireless settings /admin/status.shtml << Access point status info leak /internet/wan.shtml << WAN...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息