id: bravia-signage info: name: BRAVIA Signage - Exposure author: DhiyaneshDK severity: medium reference: - https://twitter.com/WhiteOakSec/status/1667197552461004800 - https://www.whiteoaksecurity.com/blog/sony-bravia-remote-code-execution-disclosure/ metadata: verified: "true" max-request: 1 shodan-query: title:"BRAVIA Signage" tags: misconfig,exposure,bravia,sony http: - method: GET path: - "{{BaseURL}}/#/settings" matchers-condition: and matchers: - type: word part: body words: - "BRAVIA Signage" - type: status status: - 200 # digest: 490a0046304402204668112b46be1aff3b651be86f1f095b899be3f3da8a7e2f529ffc1f593b313002203b5bae770cf5fba2ed0bcb31f002c609fab4ed83f6b1f8b12706c6c6733989f7:922c64590222798bb761d5b6d8e72950