Goby/json/Topsec-Firewall-telnet-defa...

43 lines
1.3 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Name": "Topsec Firewall telnet default account",
"Description": "天融信防火墙telnet默认口令攻击者可利用默认口令登录telnet并执行设备配置命令甚至控制整个设备。",
"Product": "Topsec-Firewall",
"Homepage": "https://www.topsec.com.cn/",
"DisclosureDate": "2020-08-11",
"Author": "itardc@163.com",
"FofaQuery": "app=\"TOPSEC-Firewall\"",
"GobyQuery": "",
"Level": "3",
"Impact": "天融信防火墙telnet默认口令攻击者可利用superman:talent口令登录telnet并执行设备配置命令甚至控制整个设备。",
"Recommendation": "修改默认口令密码最好包含大小写字母、数字和特殊字符等且位数大于8位如非必要禁止公网访问该设备白名单限制可访问IP。",
"References": [
"https://fofa.so"
],
"HasExp": true,
"ExpParams": [
{
"name": "cmd",
"type": "input",
"value": "show-running"
}
],
"ExpTips": {
"Type": "",
"Content": ""
},
"ScanSteps": null,
"ExploitSteps": null,
"Tags": [
"defaultaccount"
],
"CVEIDs": null,
"CVSSScore": null,
"AttackSurfaces": {
"Application": null,
"Support": null,
"Service": null,
"System": null,
"Hardware": ["TOPSEC-Firewall"]
},
"Disable": false
}