id: tasmota-config-webui info: name: Tasmota Configuration Exposure author: ritikchaddha severity: medium description: Tasmota configuration is exposed. reference: - https://github.com/arendst/Tasmota metadata: verified: true max-request: 1 shodan-query: title:"Tasmota" tags: misconfig,tasmota,exposure,config http: - method: GET path: - "{{BaseURL}}" matchers-condition: or matchers: - type: word part: body words: - "Firmware" - "Tasmota" condition: and case-insensitive: true - type: word part: body words: - "Theo Arends" - "