id: tasmota-config-webui info: name: Tasmota Configuration Exposure author: ritikchaddha severity: medium description: Tasmota configuration is exposed. reference: - https://github.com/arendst/Tasmota metadata: verified: true max-request: 1 shodan-query: title:"Tasmota" tags: misconfig,tasmota,exposure,config http: - method: GET path: - "{{BaseURL}}" matchers-condition: or matchers: - type: word part: body words: - "Firmware" - "Tasmota" condition: and case-insensitive: true - type: word part: body words: - "Theo Arends" - "

Tasmota

" condition: and case-insensitive: true extractors: - type: regex part: body group: 1 regex: - "Tasmota ([0-9.]+) " # digest: 4a0a004730450221009a3fb36a5c5568abcb2356994a89c068e827c0f59eda5689048364dd719c1c9c02203d3203f10e9c9017833676213cc6e692ee3c733b58d443ae8f084cf60d679ea4:922c64590222798bb761d5b6d8e72950