id: iptime-router info: name: ipTIME Router Login Panel - Detect author: gy741 severity: info description: ipTIME router login panel was detected. reference: - http://pierrekim.github.io/blog/2015-07-01-poc-with-RCE-against-127-iptime-router-models.html classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-score: 0 cwe-id: CWE-200 metadata: max-request: 1 tags: panel,login,iptime,router http: - method: GET path: - '{{BaseURL}}/sess-bin/login_session.cgi' matchers-condition: and matchers: - type: regex regex: - ipTIME ([A-Z0-9_-]+)<\/TITLE> - type: status status: - 200 extractors: - type: regex part: body group: 1 regex: - <TITLE>ipTIME ([A-Z0-9_-]+)<\/TITLE> # digest: 4b0a00483046022100933a30f274e09118ac6effc49216b8aa9c4e98e1530c3a4aa7dae1da2bd84c3002210090ad5a3b147addd17cd8959e81db383b14654244888c9321174fca8403cdca30:922c64590222798bb761d5b6d8e72950