nonamecoder / CVE-2023-22906

Proof of Concept for CVE-2023-22906

Home Page:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22906

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2023-22906

CVE-2023-22906 is a critical vulnerability that affects the Hero Qubo Smart Doorbell device running version HCD01_02_V1.38_20220125. This particular device allows Telnet access with root privileges by default, without requiring a password. This vulnerability poses a significant security risk as it can lead to unauthorized access, compromising user privacy, exposing sensitive information stored on the device and also potentially enabling the compromised device to be utilized as a cog within a botnet's malicious activities.

Research Paper

Proof of Concept Videos

Shell Access

Shell.mp4

Rickroll Chime

Rickroll.Chime.mp4

About

Proof of Concept for CVE-2023-22906

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22906


Languages

Language:HTML 100.0%Language:CSS 0.0%Language:Python 0.0%Language:C 0.0%