Path: blob/master/documentation/modules/auxiliary/scanner/http/epmp1000_dump_hashes.md
33021 views
This module exploits an OS Command Injection vulnerability in Cambium ePMP 1000 (<v2.5) device management portal. It requires any one of the following login credentials to dump system hashes:
admin/admin
installer/installer
home/home
Verification Steps
Do:
use auxiliary/scanner/http/epmp1000_dump_hashesDo:
set RHOSTS [IP]Do:
set RPORT [PORT]Do:
run